The repository has no security policy, and several workflows grant write access without consistently declaring permissions. An install-time script also adds operational risk, although the package is documented, licensed, tested in the repository, and backed by an organization.
62%
Total Score
63
100
100
60
There were zero commits and zero active maintainers during the last three months, a concrete sign that maintenance activity has recently stalled despite continued registry releases.
One workflow uses pull_request_target, but no untrusted checkout or script-injection patterns were detected across the five analyzed workflows; the remaining concern is limited to the privileged trigger.
A post-autoload-dump install script runs during Composer installation, creating some supply-chain and installation complexity that consumers should account for.
The repository has three open pull requests and only one open issue, but no issues or pull requests were opened or merged in the last month, providing limited evidence of current responsiveness.
The repository has no SECURITY.md or equivalent security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nuwave/lighthouse Version ^6.66 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
mll-lab/graphql-php-scalars Version ^6.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.