check if all the keys are available in all the .env files.
65%
Total Score
50
100
100
50
A post-autoload-dump install-time script is present, adding a small execution-surface concern for consumers, though this is a standard Composer lifecycle hook rather than evidence of abandonment.
Only one registry account has publish access. The matching user-owned repository and recent release activity provide some compensation, but the publishing base remains narrow.
The registry namespace and repository are owned by the same individual, confirming consistent ownership, but the owner type is a user rather than an organization and does not provide organizational backing.
The repository recorded zero commits and zero active maintainers in the last three months. A recent push and release history partly offset this, but the short-term inactivity still raises maintenance concern.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral alongside the lack of backlog, but provides little evidence of current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.