Clear licensing, documentation, repository tests, and a small runtime dependency set support adoption. Single-maintainer ownership leaves little redundancy if support stops.
48%
Total Score
33
100
86
33
The package has only one release, published about 2 years and 10 months ago, with no releases in the last 12 months. That is a substantial maintenance concern despite the stable 1.0.0 version.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with the one-release history, this points to weak ongoing development activity.
All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, but the confirmed workflow issue still materially raises automation risk.
The package uses a post-autoload-dump install script. This is a legitimate Composer integration point, but it adds install-time behavior that should be understood before adoption.
Only one registry account has publish access, and the project is owned by an individual rather than an organization. This creates limited redundancy if the maintainer becomes unavailable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.