The package has a clear license, repository tests, and a matching source repository. Its organization-backed project is not archived, but the workflow setup and limited maintenance history warrant care before adopting it.
55%
Total Score
75
86
50
The package runs a post-autoload-dump install-time script. This is a supply-chain and installation-behavior consideration, though one script alone is not evidence of severe risk.
Only two releases were published, both close together, with no releases in roughly 20 months. That materially raises abandonment and freshness concerns.
There were no commits and no active maintainers in the last three months, consistent with maintenance having stopped for roughly 14 months since the last push.
No security policy was found, leaving vulnerability reporting and response expectations undocumented for a package that protects production database migrations.
Version 0.0.2 is not a stable major release, so compatibility and maturity are less established than for a mature 1.x or later package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-backup Version ^9.2 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
nunomaduro/laravel-console-menu Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.