The repository includes tests, a changelog, release notes, and a matching source tree, while the MIT licensing is clear. This is a first release with no observed commit activity yet, and its workflows use unpinned actions with one workflow granting broad write access.
68%
Total Score
67
100
79
63
A post-autoload-dump install script is present. This adds execution during installation, but the signal does not show harmful behavior, so it is a modest transparency consideration rather than a severe health risk.
One registry maintainer is consistent with the repository being organization-owned, but the signal still shows a narrow publishing access base.
This is the first release, published today, with only one release and no established release cadence. That leaves maintenance maturity unproven.
No commits or active maintainers were observed in the last three months. Because the project is newly released today, this mainly means maintenance capacity is not yet established rather than proving abandonment.
Composer build tooling is present, but no security scanning tools were detected. For a package handling authorization and signed assertions, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.