Usable with caveats: the package is licensed, not deprecated, backed by a matching repository, and has tests and CI tooling. Maintenance is still lightly demonstrated, with only two releases and no commits in the last three months, while the README remains largely a template and workflow permissions need review.
62%
Total Score
50
100
83
60
One workflow uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can grant elevated repository context. No untrusted checkout or script-injection pattern was detected, which limits the concern.
A post-autoload-dump script runs during installation, which adds some supply-chain exposure, but this is a conventional Composer lifecycle hook and no additional dangerous behavior is shown here.
The published artifact includes a README and changelog, and the repository contains tests and a changelog. The missing tests in the artifact is normal packaging practice, but the README's unfinished description and template text reduce consumer transparency.
The registry namespace and repository are owned by the same individual account, which provides consistent ownership but not the redundancy of an organization-backed project.
The package is 287 days old but has only two releases, with a median interval of about 166 days. That establishes limited release history and leaves maintenance maturity less proven.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.