Usable with caveats: the package is licensed, documented, tested in its repository, and not deprecated or archived. However, it has had only one release since May 2024, no commits in the last three months, and relies on a single maintainer, so future support is uncertain.
62%
Total Score
50
100
83
63
One workflow uses pull_request_target, which can be risky when handling untrusted pull requests. No untrusted checkout or script-injection patterns were detected, limiting the concern.
A post-autoload-dump install-time script is present. This is an extra installation action, but the signal provides no evidence that it is harmful or unusual for this package.
Only one account has registry publish access, leaving a thin publishing base. The linked repository is personally owned, so there is no organization backing shown to compensate for that concentration.
The registry namespace and repository owner match, but the owner is an individual user rather than an organization. This supports package identity but does not provide organizational continuity.
This is the only release, published about 2 years and 4 months ago, with no releases in the last 12 months. That limited release history raises uncertainty about ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^11.0 | — | — |
illuminate/support Version ^11.0 | — | — |
illuminate/database Version ^11.0 | — | — |
illuminate/contracts Version ^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.