Repository activity is quiet, with no commits in the past three months and four pull requests still open. Workflows also use broad write permissions, unpinned actions, and a high-confidence bot-condition warning, although the package has clear licensing, documentation, tests, and release notes.
58%
Total Score
50
100
94
50
The package runs a post-autoload-dump script during installation. This is a lifecycle hook that deserves awareness, but the signal provides no evidence that it performs unsafe actions.
The repository is owned by an individual account rather than an organization, so the single registry maintainer reflects a genuinely thin visible backing structure.
The package has made no releases in the past 12 months after three releases clustered in February 2025, which weakens confidence in ongoing maintenance. The short historical release interval does not compensate for the prolonged silence.
The repository recorded zero commits and zero active maintainers in the past three months. This is direct evidence of currently quiet maintenance and raises abandonment risk.
There are no open issues and four open pull requests, but none were merged or newly opened in the past month. The unmerged pull requests support the broader picture of limited recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.