The package is well documented, tested, licensed, and has released twice in the last year. Recent repository work has stopped, while the single maintainer, absent security tooling, and unpinned workflow actions leave meaningful maintenance and build-integrity concerns.
62%
Total Score
67
100
83
83
Only one registry account has publishing access, and the repository owner is an individual rather than an organization. This creates a limited continuity buffer if that maintainer becomes unavailable.
The repository recorded zero commits and zero active maintainers in the last three months. Although the package released twice in the last year, the current lack of source activity raises maintenance risk.
The repository has zero stars and forks and one watcher. Low adoption is not a verdict by itself, but it means there is little visible community support to compensate for a small maintainer base.
Composer build tooling is present, but no security-scanning tool was detected. Tests and recent releases partly compensate for the tooling gap, so this is a moderate transparency concern rather than a severe risk.
The repository has no security policy. For a small Laravel package this is a hygiene gap, but the tested source and clear repository structure provide some compensating transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version >=11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.