Recent releases, active commits, repository tests, and a security policy support dependable maintenance. The package uses an install-time Composer script, so deployments should account for that behavior.
78%
Total Score
100
100
75
The package runs a post-autoload-dump Composer script during installation. Install-time execution adds supply-chain and deployment complexity, even though no other provided signal shows that the script is unsafe.
All four workflows were analyzed successfully, with all 12 action references pinned and no untrusted checkouts or script-injection findings. However, the changelog workflow has a high-confidence template-injection finding; template injection alone is a workflow hygiene concern, not a severe verdict by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^12.61.1|^13.12.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.