The repository includes tests, a changelog, and a release for this version, providing useful maintenance evidence. Recent commit activity is absent, while workflow pinning and security-policy gaps reduce confidence in ongoing care.
67%
Total Score
50
100
94
50
The package uses post-autoload-dump and post-update-cmd scripts, which are relevant install-time behavior and add some operational surface, but no evidence here shows they are unsafe.
The repository is owned by a user account rather than an organization, so the single registry maintainer provides limited visible organizational backing.
The package has existed since May 2021 with 19 releases and a median interval of about 60 days, but only one release appeared in the last 12 months, indicating slower recent activity.
There were no commits and no active maintainers in the three months before collection. The recent repository push and published release provide some compensation, but the current development pause remains a maintenance concern.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ruflin/elastica Version ^8.0 | — | — |
laravel/framework Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.