The package is licensed, documented, and backed by repository tests and a security policy. Its CI also uses an unpinned container image, adding supply-chain hygiene risk.
46%
Total Score
0
70
75
Only two releases were published, with none in the last five years; the latest release was in October 2021. This is strong evidence of abandonment risk despite the short initial release interval.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing no release activity for nearly five years.
The repository has only 6 stars and 2 forks, offering little evidence of broad community support. This is supporting evidence for the maintenance concern, not a verdict by itself.
Both workflows were analyzed and no dangerous triggers or untrusted checkouts were found, but all four action references are unpinned and a high-confidence unpinned container image was identified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^8.37 | — | — |
facade/ignition-contracts Version ^1.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.