The package includes tests, a changelog, a security policy, and a recent release. Maintenance is concentrated in one contributor, while the workflow audit found a high-confidence bot-condition issue and all seven action references are unpinned.
64%
Total Score
67
94
75
A post-autoload-dump install-time script is present. This adds execution surface during installation, but the signal alone does not show harmful or unexpected behavior.
The project has released 18 times since February 2022 and published one release in the last 12 months, including this recent version; the low recent cadence warrants some caution.
One contributor made all commits during the last 3 months, leaving maintenance dependent on a single active contributor.
Only one commit was recorded in the last 3 months, indicating limited recent development activity even though the repository was recently updated.
The audit completed all three workflows and found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. All seven action references are unpinned, and one workflow grants top-level write permissions, creating additional CI supply-chain hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^13.0 || ^12.0 | — | — |
web-token/jwt-library Version ^4.1 | — | — |
spatie/laravel-package-tools Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.