The repository includes a complete test suite, release notes, and a matching package source. It is newly published, has one individual maintainer, and contains a high-confidence workflow permission concern; monitor future releases closely.
62%
Total Score
67
100
81
67
Registry publishing access is held by one individual, leaving a thin visible maintainer base for long-term continuity.
The repository is owned by an individual rather than an organization, so there is no provided evidence of institutional backing to offset the single-maintainer risk.
The package is 0 days old with two releases and no established release interval, so maintenance consistency cannot yet be demonstrated.
The repository uses Composer build tooling, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, so the reporting and response process for vulnerabilities is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^12.0|^13.0 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/support Version ^12.0|^13.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.