Maintenance capacity is narrow, with all seven recent commits from one contributor. The long release history and current repository activity are reassuring, but they do not offset the package's registry status and identity concern.
18%
Total Score
75
50
75
50
The package is flagged as borrowing the identity of laravel/sanctum, with borrows_lookalike_identity true; consumers may have intended that established package instead.
Packagist marks the entire package as abandoned, which is a severe adoption risk even though the registry lists a replacement with the same name.
The package declares 13 runtime dependencies, including many Laravel Enso components, which increases the maintenance surface and coupling for adopters.
All 7 recent commits came from one contributor, concentrating maintenance knowledge and increasing continuity risk; organization backing provides some ability to hand work off.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package handling uploaded spreadsheet data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-enso/io Version ^2.0 | — | — |
laravel-enso/core Version ^12.0 | — | — |
laravel-enso/enums Version ^3.0 | — | — |
laravel-enso/excel Version ^3.0 | — | — |
laravel-enso/files Version ^5.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.