Documentation is thorough, and the repository includes tests, release notes, and a security policy. Maintenance is concentrated in one contributor, while workflow permissions, unpinned actions, and a high-confidence bot-condition warning add operational risk.
67%
Total Score
63
94
100
Only one account has registry publishing access. The repository is also user-owned rather than organization-owned, so there is no provided organizational backing to offset the concentrated maintainer base.
The package and repository share the same user owner, confirming the repository relationship, but the owner type is User rather than Organization and does not provide broader backing.
One contributor made all 23 commits in the last three months, giving the project a single-maintainer bus factor and increasing continuity risk if that contributor becomes unavailable.
Composer build tooling is present, but no security-scanning tool was detected. This is a hygiene gap, partially offset by the repository's separate security policy.
All five workflows were analyzed, but all 14 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a caution rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3.8 | — | — |
spatie/period Version ^2.4 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
staudenmeir/belongs-to-through Version ^2.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.