The repository has had no commits for nine months, and one registry maintainer provides limited visible maintenance capacity. All workflow actions are unpinned, with a high-confidence bot-condition warning and two workflows granting write access.
52%
Total Score
50
79
50
The package runs a post-autoload-dump install-time script. This is not necessarily unsafe, but it adds installation behavior that should be understood before adoption.
Only one account has registry publish access. The repository is user-owned, so the small maintainer base gives little redundancy if that maintainer becomes inactive.
The repository is owned by an individual rather than an organization, so there is no visible organizational backing to offset the limited maintainer base.
The package published 22 releases, all within the first day, then had no recorded releases for roughly nine months. This shows an intense initial burst but limited evidence of ongoing maintenance.
There were no commits and no active maintainers during the last three months, consistent with roughly nine months since the last push. This is a meaningful abandonment concern for a newly published package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
moneyphp/money Version ^4.5 | — | — |
archtechx/money Version ^0.5.1 | — | — |
filament/filament Version ^3.0 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.