Documentation, tests, and release notes support day-to-day use. The single active contributor and unpinned workflow actions leave modest maintenance and build-integrity concerns.
68%
Total Score
50
100
50
The repository is owned by a personal user account rather than an organization, so the concentrated contributor activity is not visibly offset by organizational backing.
One contributor made all 3 commits in the last 3 months, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
There were 3 commits in the last 3 months and 1 active maintainer. The recent activity is real but limited, so it provides only moderate maintenance assurance.
The repository has no security policy. This is a transparency and response-process gap for a package handling application data, though it is not evidence of a security defect by itself.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and it avoids top-level write permissions. However, all 4 action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/database Version ^12.0 || ^13.0 | — | — |
spatie/laravel-data Version ^4.14 | — | — |
spatie/laravel-query-builder Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.