The source includes tests, a changelog, a clear license, and automated dependency scanning. No registry release has appeared for more than three years, repository work has stopped, and the release workflow has high-confidence automation concerns plus no pinned actions.
45%
Total Score
50
100
71
50
Only three releases exist, with no release in the last three years; this is strong evidence of abandonment risk despite the initially short release interval.
There were no commits and no active maintainers in the last three months, reinforcing the release-history evidence of stalled maintenance.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is serious hygiene risk but not independently catastrophic.
The package runs a post-autoload-dump install-time script. This adds execution during installation and warrants caution, although the signal does not show a destructive or unusual script.
There are no new or closed issues or pull requests in the last month, while three pull requests remain open; this suggests limited current project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tuupola/ksuid Version ^2.1 | — | — |
illuminate/contracts Version ^9.0|^10.0 | — | — |
godruoyi/php-snowflake Version ^2.1 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.