Usable with caveats: the package is clearly identified, licensed, tested, and backed by a structured repository, but maintenance has slowed. There have been no releases in about 14 months and no commits or active maintainers in the last three months.
65%
Total Score
75
100
89
75
One workflow uses pull_request_target for Dependabot auto-merge, which warrants care because that workflow class can expose elevated repository context. No untrusted checkouts or script-injection patterns were detected, limiting the concern.
The package has five releases since September 2022, but no release in the last 12 months and the latest release was about 14 months ago. That materially raises maintenance and abandonment concerns.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the absent registry releases over the last year, this is the main reason to treat the package cautiously.
There are no open issues and four open pull requests, but none were opened or merged in the last month. The lack of issue backlog is positive, while the inactive pull requests suggest limited recent project movement.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, so this does not make the package unfit, but it provides little independent evidence of broad community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dom-crawler Version 7.4.x-dev | — | — |
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 | — | — |
symfony/css-selector Version 7.4.x-dev | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.