Unfit to use despite recent releases and solid packaging. The registry marks the package as abandoned, and the linked repository does not identify or mention this package; maintenance is also controlled by one contributor.
22%
Total Score
75
67
63
Packagist marks the entire package as abandoned, with no distinct replacement identified. Although the release history is active, package-level deprecation makes this release unsuitable for a new dependency.
One workflow uses pull_request_target and another uses workflow_run, both requiring careful trust-boundary handling. No untrusted checkout or script-injection patterns were detected, so the workflow risk is limited rather than severe.
One contributor made all 16 commits in the last 3 months, leaving no demonstrated backup maintainer. This increases continuity risk for a user-owned project.
The repository name does not match the package name, and its README does not mention the package. That raises a concrete concern that the published package may be associated with the wrong or repurposed repository.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this does not independently make the package unsafe, but it provides no additional evidence of community adoption.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.