The README is largely template text, and the repository has no security scanning or policy. It is licensed, tested in the repository, and not deprecated, but its small release history offers limited evidence of maturity.
58%
Total Score
50
100
78
50
A post-autoload-dump install-time script runs during Composer operations, adding execution complexity and a modest supply-chain exposure compared with a package without lifecycle scripts.
The package is only 190 days old with three releases and a median interval of about 95 days, so its maintenance history is still limited.
The repository recorded zero commits and zero active maintainers in the last three months, leaving little evidence of ongoing maintenance despite a recent release.
The repository has zero stars, forks, and watchers. This is not decisive for a young package, but it provides no supporting evidence of adoption or community review.
Composer is used as the build tool, but no security scanning tools are configured, reducing automated coverage for dependency and repository risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.