Usable with caveats: it is a small, clearly licensed package with tests, release notes, and a matching repository, but it has had only one registry release in about 1 year 10 months and no commits in the last 3 months. Workflow permissions and the absence of a security policy add operational concerns.
60%
Total Score
50
92
50
One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkouts or script-injection patterns were detected, so the workflow concern is limited rather than severe.
This is the only release, published about 1 year 10 months ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance and compatibility work.
The repository recorded no commits and no active maintainers in the last 3 months. Although the repository is not archived and has a later push recorded, recent development activity is still unproven.
No security policy is present in the repository, leaving no documented process for reporting or handling vulnerabilities.
Three workflows declare top-level write permissions, while two do not declare top-level permissions. Broad or implicit workflow permissions increase the repository's automation exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.