The repository is organized, licensed, documented, and backed by an organization, but its automation has high-confidence workflow hygiene problems. Dependence is reasonable only with caution because the published release is substantially older than the latest repository activity.
58%
Total Score
75
100
94
50
Only three releases were published, with the latest on February 8, 2022 and none in the last 12 months. That is a substantial maintenance concern for a framework integration, despite the relatively quick early release interval.
There were no commits and no active maintainers in the most recent three months. Combined with the old latest release, this leaves current maintenance capacity uncertain.
The repository has no security policy. For a small package this is a transparency gap, though it is less significant than the maintenance and workflow concerns.
All 11 action references are unpinned, and the audit found high-confidence bot-condition and unpinned-container-image issues. A pull_request_target workflow also has top-level write permissions, although no untrusted checkout or script injection was found; together these warrant caution rather than a severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^8.73|^9.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.