Usable with caveats: the package is clearly backed by a matching repository, has a recent stable release, tests, release notes, and security tooling. However, there have been no commits or active maintainers in the last three months, and the workflow permissions need tightening.
72%
Total Score
50
100
100
80
One workflow uses pull_request_target, which warrants care because it can run with elevated repository context. No untrusted checkout or script-injection patterns were detected, limiting the concern.
The registry namespace and repository owner match the same individual, which is consistent with a small personal open-source project. It provides direct ownership alignment but leaves a relatively narrow maintenance base.
The repository recorded no commits and no active maintainers during the last 3 months. The recent release partly offsets this, but the current maintenance pace is a meaningful caution.
There are no open issues and two open pull requests, but no issues or pull requests were merged during the last month. This gives limited evidence of ongoing responsiveness.
Four of five workflows omit top-level permissions, and the Dependabot auto-merge workflow grants write access. Explicit least-privilege permissions would improve workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.