Clear documentation, repository tests, licensing, and a small dependency set support transparency. Those strengths are outweighed by the release being withdrawn and the source repository being archived, leaving this dependency unfit for new adoption.
12%
Total Score
0
100
57
100
Packagist marks the entire package as abandoned with no replacement, directly signaling that this release should not be selected for a new dependency.
The package has only three releases and no releases in the last 12 months; its latest release was nearly three years ago, which reinforces abandonment concerns.
The repository recorded no commits and no active maintainers in the last three months, providing no evidence of current maintenance capacity.
The linked repository is archived, and its last push was about 18 months ago, indicating the project is no longer maintained through its normal source channel.
All 11 analyzed action references are unpinned, four workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. There is no untrusted checkout or script injection, which limits the severity of the workflow concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/support Version ^3.0 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.