A single release and no commits in the last three months limit confidence in ongoing maintenance. The repository has tests, a changelog, matching package documentation, and Dependabot, but workflow permissions and an unsafe bot check add maintenance risk.
62%
Total Score
50
100
89
63
A post-autoload-dump script runs during installation, adding some execution surface, but this signal alone does not show unsafe behavior.
One registry maintainer is consistent with the repository being owned by the same individual, but it leaves little apparent publishing redundancy.
The registry namespace and repository are owned by the same individual, providing consistent ownership context but no organization-level backing.
This is the only release, published 482 days ago, with no releases in the last 12 months; that limits evidence of sustained maintenance.
There were no commits and no active maintainers in the last three months, weakening evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.