Usable with caveats: the package is clearly backed by a matching repository with documentation, tests, releases, and sensible dependencies. However, it has had no commits or active maintainers for about five months, while workflow permissions and the lack of a security policy add maintenance and transparency concerns.
62%
Total Score
75
100
94
50
One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script injection was detected, but this privileged workflow deserves review before relying on the repository's automation.
All three releases occurred within about two days, and there has been no new registry release for roughly eight months. This shows an initial release burst but limited evidence of sustained release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, a significant warning for a diagnostics tool that may need updates as Laravel and security practices change.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a package that advertises security analysis.
Two workflows grant top-level write permissions and two omit top-level permission declarations, which is weaker least-privilege hygiene than expected for repository automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.