Documentation, licensing, repository tests, and a matching source tree give consumers useful transparency. A single maintainer and low adoption leave limited evidence of long-term support.
52%
Total Score
50
100
86
50
The package runs a post-autoload-dump lifecycle script. That is a review point for installation behavior, but the signal alone does not show an unsafe or unusually broad action.
Only one registry maintainer is listed. The matching user-owned repository provides some continuity, but the project still has a thin publishing and ownership base.
The latest release was about 18 months ago, and there were no releases in the last 12 months. This is a meaningful maintenance concern for a young package with only eight releases.
There were no commits and no active maintainers in the last three months. A recent repository push is not evidence of ongoing development, so maintenance capacity is currently uncertain.
The repository has no security policy. For a package that collects analytics data and exposes application routes, the missing reporting guidance reduces transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.