The package has clear documentation, repository tests, a matching source repository, and a small runtime dependency set. Its MIT licensing and Dependabot support are reassuring, though the project is still early-stage.
58%
Total Score
50
100
94
50
All 12 action references are unpinned, and three workflows grant top-level write permissions. More seriously, the high-confidence bot-conditions finding in the Dependabot auto-merge workflow indicates a potentially spoofable actor check; no untrusted checkout or script-injection sink was found.
The package uses a post-autoload-dump lifecycle script. This adds install-time behavior and deserves awareness, but the signal alone does not show that the script is unsafe or unusually broad.
The repository and registry are owned by the same individual account rather than an organization. That is consistent ownership, but it also means the project has no observed organizational backing to broaden maintenance capacity.
Only one release has been published, with no established release cadence yet. At 166 days old, this indicates an early-stage project rather than proven long-term maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. With only one release, this is meaningful evidence of currently weak maintenance momentum.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.