The repository is still active and has tests, release notes, and a clear MIT license. Maintenance is concentrated in one contributor, and the automation lacks pinned action references and a security policy.
38%
Total Score
75
70
50
Packagist marks the entire package as abandoned and names projektgopher/laravel-ffmpeg-tools as its replacement. This is a direct warning against taking a new dependency on this package.
All recent commits came from one contributor, so maintenance depends on a single person and has limited visible handoff capacity.
The linked repository name does not match the package name and its README does not mention this package, creating uncertainty about whether the repository directly represents this release.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Both workflows were analyzed with no untrusted checkout, injection, or high-confidence audit findings. However, all 5 action references are unpinned, which leaves build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.