The release includes a substantial README, changelog, license, repository tests, and a security policy. Organization backing helps offset the single-contributor history, but this is still a first-day release and every workflow action reference is unpinned.
68%
Total Score
83
92
67
A post-autoload-dump install script adds execution during dependency installation, increasing the package's install-time behavior surface. No other evidence here shows that the script is unsafe, so this is a limited hygiene concern.
This is the first release, published less than 1 hour ago, so there is no track record for maintenance or compatibility over time. The active repository provides some compensating evidence, but maturity remains unproven.
One contributor made 100% of the 28 recent commits, creating a meaningful continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off within the project.
All 3 workflows were analyzed successfully with no untrusted checkouts, script injection, or high-severity findings. However, all 8 action references are unpinned, so workflow behavior can change as upstream actions move.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0|^13.0 | — | — |
roundly-consulting/enums-for-laravel Version ^1.0 | — | — |
roundly-consulting/reviews-for-laravel Version ^1.0 | — | — |
roundly-consulting/contacts-for-laravel Version ^1.0 | — | — |
roundly-consulting/approvals-for-laravel Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.