Usable with caveats: it is a stable, licensed package with regular releases, tests, and an active organizational owner. However, no commits or contributor activity were recorded in the last three months, and the repository lacks security scanning and a security policy.
68%
Total Score
75
100
89
50
No commits or active maintainers were recorded in the last three months. This is a meaningful maintenance concern, although the recent release history and non-archived repository provide some compensation.
The repository has no stars, forks, or watchers, limiting external evidence of adoption or community support; the organization-backed ownership and regular releases partly compensate.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is unclear.
The analyzed workflow lacks top-level token permissions and uses job-level permissions only. No write-enabled top-level permissions were found, so this is a minor workflow-hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.60 || ^3.0 | — | — |
spatie/laravel-data Version ^4.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.