The repository includes tests, release notes, a license, and a security policy. Organization ownership provides some continuity, but this release has no track record yet and its build workflows need tighter pinning.
65%
Total Score
88
100
94
75
The package declares a post-autoload-dump install lifecycle script. Composer lifecycle scripts are common, but they execute during installation and add a small amount of install-time complexity.
This is the package's first and only release, published 0 days ago, so there is no release history or demonstrated maintenance cadence yet.
One contributor made all 16 commits in the last 3 months, creating a high concentration risk. Organization backing provides some handoff capacity, but no second active contributor is shown.
All three workflows were analyzed successfully with no untrusted checkouts, script injection, high-severity findings, or broad top-level write permissions. However, all 9 action references are unpinned, leaving workflow behavior dependent on mutable action versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0|^13.0 | — | — |
roundly-consulting/enums-for-laravel Version ^1.0 | — | — |
roundly-consulting/options-for-laravel Version ^1.0 | — | — |
roundly-consulting/contacts-for-laravel Version ^1.0 | — | — |
roundly-consulting/package-toolkit-for-laravel Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.