The package has a clear README, repository tests, a changelog, frequent releases, and active recent commits. Its concentrated ownership and workflow hygiene require extra care for long-term operations.
72%
Total Score
67
100
50
The package runs a post-autoload-dump install-time script. This is a supply-chain consideration because dependency installation executes package code, though the signal does not establish that the script is unsafe.
The repository owner is an individual user rather than an organization, so there is no organizational handoff capacity to compensate for concentrated maintenance.
One contributor made all 11 commits in the last 3 months, giving the project a very low bus factor. The active release cadence helps, but does not remove the risk if that maintainer becomes unavailable.
The repository has no security policy. For a package that manages network equipment connections, this reduces the clarity of vulnerability-reporting and response expectations.
All three workflows were analyzed, but all six action references are unpinned. A high-confidence bot-conditions finding affects a pull_request_target workflow, while two workflows grant top-level write permissions; together these are meaningful workflow-hygiene concerns without proving the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.