The package includes a clear README, repository tests, and release notes for this version. Organization backing helps offset one active contributor, while unpinned workflow actions and the missing security policy remain caveats.
78%
Total Score
83
100
94
67
All 3 recent commits came from one contributor, creating a concentrated maintenance path. The organization-owned project provides some compensation but does not remove the contributor-dependence concern.
Composer build tooling is present, but no security-scanning tool was detected. For a dependency package, this is a meaningful transparency and maintenance gap, though not a severe risk by itself.
The repository has no security policy. This weakens the project's disclosure and response transparency, but does not by itself indicate that the release is unsafe to adopt.
All 4 workflows were analyzed without high-confidence audit findings or untrusted checkouts, but all 11 action references are unpinned and 2 workflows grant top-level write permissions. These are workflow hygiene concerns, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ^10.18||^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^10.18||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
mindtwo/laravel-auto-create-uuid Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.