Healthy and reasonable to adopt, with a small maintainer base as the main concern. It has frequent releases, a current stable version, repository tests and tooling, and no deprecation or archive signal, but recent commits come from one contributor and workflow permissions are uneven.
78%
Total Score
50
100
100
70
The package uses a post-autoload-dump install-time script. This deserves review before adoption because installation behavior is not entirely passive, although no separate workflow-risk evidence indicates a severe concern.
The registry namespace and repository are owned by the same individual account, so the package has direct ownership alignment but no organization-level maintenance backing.
All recent commits come from one contributor, so an interruption to that contributor could leave maintenance unsupported; the individual-owned project backing does not provide an organizational handoff.
Only one commit was made in the last 3 months by one active maintainer, which is a meaningful sign of limited recent development capacity despite the strong release history.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^4.0 | — | — |
spatie/laravel-data Version ^4.4 | — | — |
illuminate/contracts Version ^12.0 | ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.