The repository includes tests, a changelog, matching package references, and dependency scanning. Its single-user ownership and small audience limit confidence in long-term support.
57%
Total Score
50
83
50
Only one registry maintainer is listed, which creates a thin publishing base. The linked repository is also owned by a user account rather than an organization, so no broader backing compensates for that concentration.
The package has only 3 releases over about 2 years, with a median interval of about 276 days and just 1 release in the last 12 months. This indicates slow maintenance, although a release in March 2026 shows the project is not abandoned.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The June 2026 push and March 2026 release provide some recent activity, but the current pause weakens maintenance confidence.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, though it is a transparency gap rather than evidence that the package is unsafe to depend on.
Version 0.3.0 is not a prerelease, but the package has not reached a stable major version. This is a modest maturity concern rather than a release-blocking problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.