The release is licensed, documented, tested in its repository, and has a matching source project with a security policy. Its maintenance has ended, and the repository and package are no longer supported; the workflows also use an unpinned container image.
12%
Total Score
50
50
100
Packagist marks the entire package as abandoned, with no replacement named. This is a severe adoption and support risk rather than a cosmetic metadata issue.
The package has had no release in more than 3 years and no releases in the last 12 months. Combined with the archived repository, this indicates sustained abandonment rather than a temporary pause.
There were 0 commits and 0 active maintainers in the last 3 months. The archived state and release gap reinforce that there is no current maintenance capacity.
The linked repository is archived, and its last push was on March 24, 2023. An archived source project is a strong indication that maintenance and issue response have ended.
Both workflows were analyzed and have no untrusted triggers or script-injection sinks, but all 4 action references are unpinned and a high-confidence finding reports an unpinned container image. This weakens build reproducibility and workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^8.37 | ^9.0 | ^10.0 | — | — |
spatie/data-transfer-object Version ^3.7 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.