The project has an organization behind it, a real README, tests, release notes, security scanning, and a matching repository. Maintenance has already gone quiet, while workflow permissions, unpinned actions, and a high-confidence bot-condition finding add practical supply-chain concerns.
58%
Total Score
75
100
89
63
A post-autoload-dump install lifecycle script runs during Composer installation, which adds execution surface for consumers even though no unsafe behavior is shown here.
The package is young, with five releases concentrated in its first year and a median interval of about 49 minutes, so its long-term maintenance record is still limited.
There were no commits and no active maintainers in the most recent three months, a concrete sign that maintenance has currently stalled despite the repository not being archived.
No issues or pull requests were opened or closed in the last month. With no commit activity either, this provides little evidence of ongoing community or maintainer interaction.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any audience provides no external maturity signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/mcp Version ^0.5.1 | — | — |
opscale-co/actions Version ^1.0 | — | — |
butschster/dbml-parser Version ^0.3.0 | — | — |
spatie/laravel-query-builder Version ^6.3 | — | — |
opscale-co/nova-package-tools Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.