The package includes tests, a substantial README, a changelog, and a matching MIT license. Its very recent history and single-contributor maintenance make long-term support less certain, while workflow permissions and unpinned actions add release-hygiene concerns.
68%
Total Score
67
100
81
75
The repository is owned by a personal user account rather than an organization, so the single-maintainer concentration is not visibly offset by organizational backing.
The package is only 59 days old, despite having 9 releases in that period; this shows active development but provides little evidence of long-term maintenance.
One contributor made 100% of the 57 recent commits, leaving the project dependent on a single person for ongoing maintenance and review.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented disclosure or response process for vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ~0.11.0 | — | — |
laravel/mcp Version ^1.0 | — | — |
spatie/laravel-data Version ^4.23 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.