The package includes tests in its repository, release notes, a clear MIT license, and a small runtime dependency surface. Its early track record and workflow configuration leave maintenance and build-integrity questions that should be monitored.
68%
Total Score
50
100
89
50
A post-autoload-dump install lifecycle script is present, adding execution during installation and therefore a modest supply-chain review concern.
The repository is owned by an individual user rather than an organization, so the single registry maintainer offers limited visible organizational redundancy.
This is the first release, published 0 days ago, with only one release recorded; there is not yet enough history to demonstrate sustained maintenance.
The repository reports zero commits and zero active maintainers in the last 3 months; because the project is 0 days old, this mainly means there is no established maintenance history yet.
The repository has zero stars, forks, and watchers. For a release published today this is weak supporting evidence rather than proof of poor quality, but it provides no external maturity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.