Clear ownership, repository tests, a changelog, and MIT licensing support adoption. The GitHub Actions setup has a high-confidence bot-condition warning, broad write permissions, and no pinned action references.
52%
Total Score
50
86
50
The registry namespace and repository are owned by the same individual, so the package has direct ownership alignment but no organizational backing signal.
Only two releases exist, with the latest published over two years ago and none in the past 12 months; this materially raises maintenance and compatibility risk.
There were no commits and no active maintainers in the past three months, indicating little recent development capacity and increasing abandonment risk.
The repository has no security policy, leaving users without a documented reporting path; this is a transparency gap for a maintained dependency.
The release is not marked prerelease, but the package remains on the 0.x line, so compatibility guarantees are weaker than for a stable major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.