Usable with caveats: the repository is active, documented, tested, and not archived, but this is a young 0.x package with only one release and all recent commits coming from one contributor. Review its install script and CI permissions before adopting it in a production project.
68%
Total Score
75
100
88
63
One of five workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkouts or script-injection patterns were detected, but this privileged workflow deserves review.
The package runs a post-autoload-dump install-time script. This is a meaningful installation-time behavior that should be reviewed, although the signal alone does not show that it is harmful.
The package and repository are owned by the same individual account rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
This package is only 90 days old and has one release, so there is little evidence of sustained release maintenance or long-term stability.
All 31 commits in the last 3 months came from one contributor, creating a substantial continuity risk if that contributor becomes unavailable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0||^13.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.