Documentation and licensing are solid, and the project has tests and recent commits. The single-contributor base and permissive, unpinned automation leave meaningful maintenance and build-integrity concerns.
58%
Total Score
60
100
88
67
A post-autoload-dump install lifecycle script runs during dependency installation. Its presence deserves attention because install-time code executes automatically, but no script behavior is provided to establish a severe risk.
The registry has one publishing maintainer. The organization-backed repository makes a short registry access list less concerning, but it does not prove a broad active maintainer base.
This is the only release, published 53 days after the package first appeared, so there is not yet enough history to establish durable maintenance.
All six recent commits came from one contributor. Organization ownership provides some handoff potential, but no second active contributor is evidenced.
Six commits from one active maintainer in three months show recent work, but the narrow activity base limits resilience if that maintainer stops contributing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0||^11.0||^12.0||^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^10.0||^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.