The project is actively released, licensed, tested, and backed by an organization, but recent work is concentrated in one contributor. Its repository has no security policy or security-scanning tooling, leaving transparency and continuity concerns.
42%
Total Score
83
50
83
83
The package borrows the identity of the much more established laravel/sanctum, with borrows_lookalike_identity true. Even though artifact overlap is 0.0, consumers may have intended to install laravel/sanctum instead, making this a severe supply-chain adoption risk.
The package declares 13 runtime dependencies and no development dependencies. This is a relatively broad runtime dependency surface, which adds some maintenance coupling but is consistent with a feature-rich Laravel Enso integration.
All 7 recent commits came from one contributor, giving the project a bus factor of one. Organization backing partly compensates for this concentration, but continuity still depends heavily on one active maintainer.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning layer is a modest transparency and hygiene concern.
The repository has no published security policy. For a package handling uploaded spreadsheets and queued processing, this weakens the project's vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-enso/io Version ^2.0 | — | — |
laravel-enso/core Version ^12.0 | — | — |
laravel-enso/enums Version ^3.0 | — | — |
laravel-enso/excel Version ^3.0 | — | — |
laravel-enso/files Version ^5.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.