This is a healthy, mature release with a long release history, frequent recent releases, stable versioning, an active and non-archived organization-backed repository, current commit activity from five contributors, strong documentation and source-tree hygiene, and no install-time lifecycle scripts. The main residual concerns are repository security hygiene: most workflows lack top-level token permissions, one workflow grants top-level write access and uses pull_request_target, and no security policy was found. These warrant review of the CI configuration but do not outweigh the package's strong maintenance, transparency, and project-backing evidence.
91%
Total Score
100
100
100
70
One of five workflows uses pull_request_target, which warrants review because it can expose privileged workflow context; however, no untrusted checkout or script-injection patterns were detected.
No repository security policy was found, leaving vulnerability-reporting and response expectations less explicit.
Four workflows lack top-level token permissions and one workflow grants top-level write access, creating avoidable CI privilege ambiguity; this is a security-hygiene concern rather than evidence of package abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/config Version ^12.0 || ^13.0 | — | — |
illuminate/support Version ^12.0 || ^13.0 | — | — |
illuminate/database Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.