The repository includes tests, a changelog, and a matching README. Workflow hardening is incomplete, and the project is too new to demonstrate sustained maintenance or security review.
68%
Total Score
75
100
88
67
A post-autoload-dump install-time script is present. This adds some installation complexity, but the signal does not show unsafe behavior by itself.
Only two releases exist, both published within about 22 minutes, and the package is less than one day old. This is expected for a new project but provides no evidence of sustained maintenance.
There were no commits or active maintainers in the previous three months, but the repository was created or updated very recently, so this is mainly a lack of historical evidence rather than established abandonment.
Composer build tooling is present, but no security-scanning tool was detected. For a package that transmits application error and user context, this is a modest transparency gap.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented for an integration handling application error data.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.