Clear licensing, release notes, and a focused dependency set make the package understandable to adopt. Maintenance capacity is less reassuring, with one publisher, no commits in three months, and limited repository security tooling.
61%
Total Score
50
100
83
63
The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign that maintenance may have stalled.
A post-autoload-dump install script is present, adding execution during Composer installation; no evidence here shows that it is unsafe or unusually broad.
Only one registry account has publish access. This is a modest resilience concern for a user-owned project because publication depends on a single person.
The repository is owned by an individual user rather than an organization, so the single-maintainer concern is not offset by visible organizational backing.
The package has 20 releases, but they were concentrated between October 13 and November 12, 2025, with a median interval of about 18 minutes; the burst is followed by roughly 10 months without a newer release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.