The package has a substantial README, release notes, repository tests, and a security policy. One contributor carries all recent commits, while workflows use broad permissions and unpinned actions; treat those as maintenance and build-hygiene caveats.
72%
Total Score
63
100
100
100
Only one account has registry publish access, which is a modest publishing continuity risk for a package whose repository is also owned by one individual.
The repository is owned by a user rather than an organization, so the single-contributor and single-publisher concentration is not offset by visible organizational backing.
All 24 recent commits came from one contributor, leaving no demonstrated active handoff capacity if that person becomes unavailable.
All five workflows were analyzed, but all 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding remains in the auto-merge workflow. The pull_request_target workflow has no untrusted checkout or script-injection finding, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-translatable Version ^6.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.