Healthy for a young package, with clear documentation, tests, a matching source repository, and recent work from two contributors. It is still early-stage with only two releases and no security policy or automated security scanning, so review updates before relying on it broadly.
82%
Total Score
88
100
78
80
A post-autoload-dump install lifecycle script runs during installation, which adds some supply-chain exposure; the provided workflow evidence is otherwise restricted and shows no dangerous workflow patterns.
The registry has one publishing maintainer, which is a modest concentration risk for a user-owned project, though repository activity shows a second active contributor.
The package is only 39 days old with two releases, so its maintenance history and compatibility record are limited despite a recent latest release.
The repository has no stars, forks, or watchers, but the package is only 39 days old; this limits supporting evidence without independently indicating poor health.
The project uses Composer build tooling, but no security scanning tools were detected, leaving a security-hygiene gap for a package that ships executable PHP and a built frontend asset.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
nckrtl/laravel-toolbar Version ^0.3.1 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.