The package is licensed and documented, and the repository includes tests plus Dependabot scanning. Its long release gap and workflow weaknesses reduce confidence in long-term support and maintenance.
62%
Total Score
50
100
94
50
The package and repository are owned by the same individual account, so there is no organization backing shown to compensate for the thin maintainer base.
This is the only release, published nearly three years ago, with no releases in the last 12 months. That leaves the package's compatibility and ongoing maintenance uncertain despite the repository being updated more recently.
The repository recorded no commits and no active maintainers in the last three months. This conflicts with the recent push timestamp and the single old release, so current development capacity is uncertain.
The repository has no security policy. For a library intended to be integrated into applications, that weakens the project's vulnerability-reporting transparency.
All 12 action references are unpinned, and three workflows grant top-level write permissions. A high-confidence bot-conditions finding affects the pull_request_target automation; although no untrusted checkout or script injection was found, these are meaningful workflow-hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.