The small codebase has repository tests, a changelog, release notes for v1.0.2, and organization backing. Maintenance appears paused: there have been no releases in 12 months and no commits or active maintainers in the last three months.
58%
Total Score
75
100
78
50
A post-autoload-dump script runs during installation; this is worth noting because install-time behavior can affect consumers, but no evidence here shows it is unsafe.
The package is 520 days old but has only three releases, all concentrated within about one day, with no releases in the last 12 months. That strongly suggests inactive maintenance, though a small stable package can need few releases.
There were zero commits and zero active maintainers in the last three months, a concrete sign that ongoing maintenance has stopped or slowed substantially.
There is one open issue and no issue or pull-request activity in the last month, offering no recent evidence of responsive maintenance.
The repository has only 2 stars, 0 forks, and 2 watchers. Low popularity is supporting context rather than a health verdict, but it provides little evidence of broad adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.