The repository has had no commits or active maintainers in the last three months, despite being only 110 days old. Automated workflows also use 12 unpinned actions and contain a high-confidence bot-condition issue; organization backing, tests, and licensing provide useful support.
62%
Total Score
63
100
89
50
There were zero commits and zero active maintainers in the last three months. For a package only 110 days old, that is a concerning maintenance gap.
All 12 action references are unpinned, and a high-confidence bot-condition finding affects the Dependabot auto-merge workflow. One pull_request_target trigger is not harmful by itself, but the workflow hygiene still lowers confidence in release automation.
A post-autoload-dump install script is present. This is a meaningful install-time behavior, but the signal provides no evidence that it is unsafe or unusually broad.
The package is only 110 days old and all 10 releases occurred on the same day, showing active initial publishing but not an established release cadence.
There are no new or closed issues in the last month and four open pull requests, with no merged pull requests. This suggests limited recent project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0|^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.