Mask Eloquent attributes on retrieval like $casts
68%
Total Score
caution
Usable with caveats: maintenance is thin, with one recent contributor and only two releases.
A post-autoload-dump lifecycle script runs during Composer installation, adding execution during setup. No more severe script behavior is shown, so this is a limited supply-chain concern.
The repository is owned by an individual user rather than an organization, so the single-maintainer concentration provides no visible organizational handoff capacity.
The package is young at 243 days and has only two releases, with a median interval of about 164 days; this provides limited evidence of long-term maintenance.
One contributor made all recent commits, giving the project a single-person maintenance dependency. The matching repository and release activity help verify ownership but do not broaden that base.
Only one commit was recorded in the last three months. Recent activity exists, but the volume is too low to demonstrate strong ongoing maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | ^11.0 | ^12.0 | ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.