Release notes, repository tests, and dependency scanning provide useful maintenance evidence. The single maintainer, no commits in three months, and workflow weaknesses leave meaningful continuity and automation risk.
62%
Total Score
50
100
94
50
Only one registry account has publish access, leaving a thin publishing base; the linked repository is user-owned rather than organization-backed, so there is little visible redundancy.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, providing limited visible project backing.
The package has existed since July 2017 with 17 releases, but it had no registry release in the last 12 months, which indicates a slower maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that current development activity has slowed.
The repository has no published security policy, which is a modest transparency gap for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.