Risky to adopt: the package has had no registry release in about two years and eight months, no recent repository commits, and a prior scan flagged this release as a supply-chain risk. It has a real repository, tests, licensing, and release notes, but those positives do not offset the stale maintenance and workflow concerns.
30%
Total Score
50
100
86
60
The package has made six releases, but none in the last 12 months, and the latest release is about two years and eight months old. This is a substantial maintenance and abandonment concern.
The repository recorded no commits and no active maintainers during the last three months, which supports the broader evidence of stalled maintenance.
One workflow uses pull_request_target, a sensitive workflow trigger. No untrusted checkout or script injection was detected, which limits the concern but does not remove the elevated workflow risk.
The package runs a post-autoload-dump installation lifecycle script. Install-time execution adds supply-chain exposure, although this signal alone does not show that the script is harmful.
Only one registry account has publish access, creating a limited publishing base. The linked personal repository provides some ownership context, but no recent activity compensates for the narrow base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version * | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.