Usable with caveats for Laravel applications. The package is clearly documented, tested, licensed, and recently released, but maintenance currently depends on one contributor and recent repository activity is very limited. Review its continued maintenance before making it a long-term core dependency.
68%
Total Score
50
100
88
80
The registry namespace and repository are owned by the same individual user, which confirms ownership alignment but provides less institutional continuity than organization-backed maintenance.
All three-month commit activity is concentrated in one contributor, named claude, creating a meaningful continuity risk for this user-owned project with no organizational handoff indicated.
Only one commit from one active maintainer was recorded in the last three months. The recent release is positive, but this thin ongoing activity leaves limited evidence of sustained maintenance.
The repository uses Composer, but no security-scanning tool was detected. That is a transparency and maintenance gap, though it is not by itself evidence that the package is unsafe.
No security policy was found in the repository, leaving vulnerability reporting and response expectations unclear for a package used in application code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moneyphp/money Version ^4.8 | — | — |
illuminate/support Version >=12 | — | — |
illuminate/database Version >=12 | — | — |
illuminate/contracts Version >=12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.