It has a long release history, a current repository, tests, and recent contributions from two developers. The package identity closely resembles laravel/sail and appears to borrow that identity, so consumers should verify they selected the intended package.
45%
Total Score
100
83
50
The package resembles laravel/sail, which has 8,533,284 monthly downloads versus 316 for this package, and borrows its lookalike identity. Although artifact overlap is 0 and the README does not identify it as a fork, the identity borrowing is strong supply-chain confusion evidence.
Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a hygiene gap rather than evidence of abandonment.
The repository has no published security policy. This is a transparency gap, though it is outweighed by the package's active release history and current source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel-enso/enums Version ^3.0 | — | — |
laravel-enso/mails Version ^1.0 | — | — |
openspout/openspout Version ^4.0 | — | — |
laravel-enso/filters Version ^3.0 | — | — |
laravel-enso/helpers Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.