Usable with caveats: the package is actively releasing, licensed, and backed by a matching repository with tests and documentation. It is only 21 days old and all recent commits come from one maintainer, so its long-term stability and continuity are not yet established.
68%
Total Score
60
100
88
80
A post-autoload-dump script runs during installation. This is a real installation-time behavior that deserves review, although the signal does not show a dangerous script or make the package unfit by itself.
Only one registry account has publish access. This is a continuity concern, though the matching user-owned repository shows the same individual is actively developing it.
The registry namespace and repository are owned by the same individual account, providing direct ownership alignment but no organizational backing for maintenance handoff.
The package is only 21 days old with five releases and a median interval of about 1.7 days. That shows active iteration but provides little evidence of long-term maintenance or stability.
One contributor made all nine recent commits, creating a complete bus-factor dependency on LenoxVDB. No organization backing or second active contributor is present to compensate for that concentration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version 4.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.