The package includes tests, a clear README, an MIT license, and release notes for this version. A lone maintainer, no security policy, and an install-time script add smaller concerns.
52%
Total Score
50
100
92
67
The package runs a post-autoload-dump install-time script. The signal does not show harmful behavior, but any install-time execution adds review surface for consumers.
One registry maintainer publishes the package, leaving little visible publishing redundancy. The linked repository is user-owned, so no organization backing compensates for this thin base.
All seven releases arrived during a single launch period on March 18, 2026, with no later releases across the following 186 days. That suggests an unproven maintenance track record.
The repository recorded zero commits and zero active maintainers during the last three months, despite the package being only 186 days old. This is a meaningful abandonment concern.
The linked repository has no security policy. This limits transparency about vulnerability reporting and response, though it is not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
microsoft/azure-storage-table Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.