The package has clear documentation, tests, release notes, and two active contributors. Its CI uses four unpinned actions, and the project is only 88 days old, so future maintenance is not yet proven.
78%
Total Score
100
100
88
75
The package is only 88 days old and has had two releases, both within the same day, so long-term maintenance and release cadence are not yet established.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest supply-chain hygiene gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that makes external API requests.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
nyoncode/laravel-package-toolkit Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.