Usable with caveats: the package is licensed, documented, tested in its repository, and not deprecated or archived. However, its last release was over two years ago and the repository has had no commits or active maintainers in the last three months, so ongoing compatibility support is uncertain.
58%
Total Score
50
100
89
63
One workflow uses pull_request_target for Dependabot auto-merge, which carries elevated workflow risk, but no untrusted checkouts or script-injection patterns were detected.
Only one registry account has publish access. That is a thin publishing base for a user-owned project and increases continuity risk if that maintainer becomes inactive.
The registry namespace and repository owner match, but the project is backed by a single user rather than an organization, providing limited visible continuity beyond that maintainer.
The package has had no releases in the last 12 months, and its latest release was over two years ago. This is a meaningful maintenance concern for a framework-integrated library, despite its history of 16 releases.
There were zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating stalled ongoing development.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
calebporzio/sushi Version ^2.5.2 | — | — |
spatie/simple-excel Version ^3.4 | — | — |
illuminate/contracts Version ^11.0 | — | — |
envor/laravel-datastore Version ^1.2.10 | — | — |
envor/laravel-schema-macros Version ^1.1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.