The MIT license, matching repository, repository tests, and changelog provide useful baseline transparency. A post-autoload-dump script and no security policy add modest operational concerns.
67%
Total Score
50
100
94
50
The package runs a post-autoload-dump lifecycle script, which adds install-time behavior that consumers should understand before adoption.
One contributor made all two recent commits, leaving maintenance dependent on a single active person and creating a meaningful continuity risk.
Only two commits were recorded in the last three months, indicating limited recent development despite the strong registry release cadence.
Composer build tooling is present, but no security scanning tools were detected, leaving an unaddressed project-hygiene gap.
The repository has no security policy, so there is no documented path for reporting vulnerabilities or explaining security handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-data Version ^4.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.