The artifact includes a clear README, changelog, complete MIT licensing, and a small dependency footprint. Its short release history and unavailable repository evidence limit confidence, while the post-autoload-dump script warrants checking before adoption.
60%
Total Score
50
100
90
75
A post-autoload-dump install-time script is present. The signal does not show that it is unsafe, but lifecycle execution adds adoption and review risk compared with a package without install-time behavior.
One registry account has publish access. This is administrative metadata rather than evidence of actual maintenance activity, so it provides little positive assurance and is not scored as a defect on its own.
The package is only 97 days old with three releases, spaced about 30 days apart. This shows active early development but provides limited evidence of long-term maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^11.0||^12.0||^13.0 | — | — |
illuminate/support Version ^11.0||^12.0||^13.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
myopensoft/php-version-bumper Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.