This is a usable, transparently packaged MIT-licensed Laravel integration with a matching repository, documented usage, repository tests, changelog, dependency automation, and no registry deprecation or install-time scripts. However, adoption carries meaningful maintenance risk: the project is controlled by one individual, has no commits or active maintainers in the last 3 months, has no stars, and remains on an unstable 0.x major version. The repository also lacks a security policy and has workflow permission and pull-request-target concerns. Overall, it appears serviceable but should be adopted with monitoring and a contingency plan rather than treated as a mature dependency.
62%
Total Score
50
100
89
70
One workflow uses pull_request_target, which requires careful handling of untrusted pull requests, but no untrusted checkout or script-injection patterns were detected in the analyzed workflows.
Only one registry account has publish access, which creates a concentration and continuity risk; the individual-owned repository context makes this a genuine bus-factor concern rather than normal organization publishing hygiene.
The repository is owned by an individual user rather than an organization, so there is no organizational backing signal to offset the single-maintainer continuity risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This conflicts with the recent registry release and materially raises the possibility of slowing maintenance or release-only activity.
There are no open issues, but two open pull requests have had no new or merged activity in the last month; this is a modest signal of limited current collaboration rather than a severe issue by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4|^8.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.