Recent commits from three contributors and release notes show the project is still cared for, with an organization behind it. The small user base and missing security policy leave less independent scrutiny, while workflow safeguards need tightening.
70%
Total Score
100
89
33
All five workflows were analyzed, but all 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects Dependabot auto-merge. The pull_request_target workflow has no untrusted checkout or script-injection finding, which limits the severity.
The package uses a post-autoload-dump install-time script. This adds execution during installation, but the signal provides no indication that the script is unusually risky.
The package has 18 releases over 991 days, but only one release in the last 12 months; this suggests a slower recent cadence despite the latest release being recent.
The repository has only 2 stars and 2 forks, so independent adoption and scrutiny appear limited; this is supporting caution rather than evidence of abandonment.
No security policy is present in the repository, leaving vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
morningtrain/economic Version ^v1.3 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.