The package includes a clear README, changelog, MIT license, and a repository that matches its name. Its single maintainer and lack of commits in the last three months leave future maintenance uncertain.
68%
Total Score
50
100
83
67
A post-autoload-dump install-time script runs during Composer operations, adding some installation complexity even though no harmful behavior is shown here.
Only one registry account has publish access, which concentrates publishing responsibility and increases continuity risk for a user-owned project.
The registry and repository are owned by the same individual account, providing consistent ownership context but no organizational backing.
Five releases occurred in the last 12 months, but the latest release was about ten months ago, suggesting activity has slowed since the initial release period.
The repository had no commits and no active maintainers in the last three months, a meaningful sign that maintenance may have paused.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
blade-ui-kit/blade-icons Version ^1.8 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.