The small maintainer base and sparse release history leave limited evidence of sustained support. The package is clearly identified, licensed, tested, and not archived, but its automation needs attention.
62%
Total Score
63
100
94
50
Only one registry account has publish access, limiting publishing redundancy, though the repository is also clearly tied to that same individual project owner.
The package has six releases over about three and a half years, but only one release in the last 12 months and a median interval of about 349 days indicate a slow cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is meaningful evidence of currently weak maintenance activity despite the recent release.
There are no open issues, but five open pull requests have had no new or merged activity in the last month, suggesting limited current review throughput.
No repository security policy is present, leaving disclosure guidance undocumented; this is a transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
illuminate/validation Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.