The package has a clear README, repository tests, release notes for this version, and an MIT license. Dependabot and Composer tooling provide useful project support despite its small footprint.
62%
Total Score
50
100
100
50
Only one account has registry publish access, leaving limited publishing redundancy. The matching user-owned repository and recent release activity partly compensate, but a single maintainer remains a continuity concern.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful recent maintenance gap, even though the release history shows activity over the past year.
No repository security policy was found, reducing transparency for vulnerability reporting. This is a hygiene gap rather than evidence that the package is unsafe.
All 12 analyzed action references are unpinned, and one workflow has a high-confidence bot-conditions finding; one workflow also grants top-level write permissions. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these are workflow hygiene and automation risks, not severe evidence on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/regex Version ^3.1 | — | — |
nesbot/carbon Version ^2.64|^3.6 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.