This is a healthy, actively maintained release with a five-year history, nine releases in the last 12 months, a stable non-prerelease version, and no registry deprecation. The linked repository is active and unarchived, matches the package, contains tests and changelog material, uses Composer and Dependabot, and publishes a security policy. The main risks are a single active maintainer with all recent commits, very low repository popularity, an install-time post-autoload-dump script, and some GitHub Actions workflows with broad or unspecified token permissions; these warrant review but do not outweigh the strong release and repository maintenance evidence.
82%
Total Score
70
100
94
70
Six workflows were analyzed; one uses pull_request_target, but there are no untrusted checkouts or script-injection findings. The isolated pull_request_target usage merits review but is not severe on the available evidence.
The package declares a post-autoload-dump install lifecycle script. This adds installation complexity and should be reviewed before adoption, although the signal alone does not establish that the script is unsafe or damaging.
Only one registry account, Maurizio, has publish access. This is a real publishing continuity concern, though the repository shows ongoing activity from the same maintainer.
The repository owner is an individual user rather than an organization. Combined with the single recent contributor, this provides less maintenance redundancy than organization-backed ownership.
One contributor made all 4 commits in the last 3 months, giving a 100% top-contributor share. This creates a meaningful continuity and bus-factor concern for a user-owned project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.