Risky to adopt for new projects: the package has had no release or repository activity for about four years, despite having solid basic documentation, tests, and licensing. It is not deprecated or archived, but its long inactivity makes future compatibility and maintenance uncertain.
45%
Total Score
0
100
71
88
The last release was in June 2022, and there have been no releases in the last 12 months; after about four years without a release, maintenance and compatibility risk are substantial.
The repository had zero commits and zero active maintainers in the last three months; combined with the old last release, this strongly indicates the project is inactive.
Composer-based build tooling is present, but no security scanning tools were detected; this is a minor transparency and assurance gap rather than a severe defect.
Neither analyzed workflow declares top-level token permissions, so the repository does not visibly constrain GitHub Actions token access; no write permissions were explicitly observed.
The assessed release is not a prerelease, but the package remains on the 0.x major line, so its API stability is less certain and the long period without updates provides no recent compatibility evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^8.37|^9 | — | — |
spatie/laravel-package-tools Version ^1.4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.