The package includes a clear README and MIT license. The repository could not be found, limiting verification of maintenance and provenance.
57%
Total Score
75
50
The package runs a post-autoload-dump install-time script. Composer lifecycle hooks can be legitimate, but they add execution and review risk compared with a package that has no install scripts.
The package has four releases across about 811 days, with one release in the last 12 months and a median interval of about 302 days. This indicates slow maintenance rather than abandonment, so it lowers confidence.
Version v0.3.0 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which partly offsets the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^13.0||^12.0 | — | — |
illuminate/contracts Version ^13.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
hexafuchs/laravel-dynamic-artisan-commands Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.