Usable with caveats: it has a stable release history, an active-looking repository, tests, licensing, and recent releases, but repository commits have stopped for three months. The README is largely an uncustomized template, and workflow permissions plus the missing security policy reduce transparency.
68%
Total Score
50
100
89
50
Five workflows were analyzed with one pull_request_target workflow, used for Dependabot auto-merge. No untrusted checkouts or script-injection patterns were detected, so the workflow setup warrants review but is not severe on the available evidence.
The package runs a post-autoload-dump install-time script. This adds installation behavior that should be reviewed, although the signal does not show a dangerous command or unusual script count.
The release includes a README and changelog, while the repository has tests and a changelog; the missing published tests are normal packaging practice. However, the README still contains prominent template text rather than package-specific documentation.
The registry namespace and repository owner match, so the package has consistent ownership backing. The owner is an individual account, making the single-person maintenance model more relevant.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern despite the package's recent release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version >=8.0 | — | — |
spatie/laravel-package-tools Version >=1.12 | — | — |
ianrothmann/langserve-php-client Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.