It has a clear MIT license, a useful README, repository tests, and no install-time scripts. The small user-owned project lacks a security policy and its workflow uses unpinned actions; pin v1.0.1 while its maintenance record develops.
62%
Total Score
50
100
93
75
The package is about three months old and has only two releases, both published on the same day, so long-term maintenance and release discipline are not yet demonstrated.
There were no commits and no active maintainers during the last three months. For a package only about three months old, this leaves its maintenance capacity unproven rather than showing an established abandoned project.
The repository has no security policy. This is a transparency and incident-reporting gap for a package that changes Laravel defaults, although it is not evidence of a security defect.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.