Clear documentation, tests, release notes, and licensing make adoption straightforward. The project is still young, has one publisher, no commits in three months, and leaves all workflow actions unpinned.
62%
Total Score
50
100
88
50
A post-autoload-dump install-time script is present, which adds execution during installation. This is a limited supply-chain hygiene concern, though the signal does not show that the script is malicious or unusually broad.
Only one registry publishing account is listed. The repository is also owned by a single user, so there is no organization backing shown to compensate for the thin maintainer base.
The package is only 143 days old with two releases, and both releases occurred within the last 12 months. This shows initial activity but provides little evidence of long-term maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. For a package only a few months old, this is a meaningful sign that maintenance may have slowed.
The repository has zero stars, forks, and watchers. For a package this young, this is weak supporting evidence rather than proof of poor quality, but it provides no external adoption signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.