The package has regular releases and a clear repository with tests, documentation, and security guidance. Its automation setup still needs attention before relying on it for critical production work.
67%
Total Score
50
100
100
75
The package runs a post-autoload-dump script during installation. This is an extra install-time action and merits awareness, but the signal provides no evidence that it is unsafe or unrelated to the package.
The repository is owned by the individual account RealZone22 rather than an organization, so the small apparent maintainer base provides limited redundancy. Recent releases and repository activity offer some compensation.
The repository recorded no commits and no active maintainers in the last 3 months, which is a meaningful maintenance slowdown. A recent release and one merged pull request partly offset this, but do not remove the concern.
All four workflows were analyzed, but all 10 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a hygiene and review concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
gehrisandro/tailwind-merge-laravel Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.