A lightweight dependency health dashboard for Laravel applications
78%
Total Score
healthy
Active but very young, with every recent commit from one maintainer and unusually rapid releases.
The package declares post-autoload-dump and post-update-cmd Composer scripts, adding install or update-time behavior. These are common Composer hooks, but they warrant awareness when installing the dependency.
The registry and repository are owned by the same individual account rather than an organization. This matches the single-maintainer activity profile and provides no organizational handoff evidence.
The package is only 151 days old, with 10 releases in that period and a median release interval of about 1.3 hours. This shows active iteration but an unusually compressed cadence for a young package.
One contributor made all six commits in the last three months, giving the project a 100% top-contributor share. With user-owned rather than organization-backed project ownership, this is a real continuity risk.
There were six commits in the last three months, showing recent maintenance. All were made by one active maintainer, so continuity depends heavily on that person.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.0||^8.0 | — | — |
illuminate/database Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
laravel/slack-notification-channel Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.