The package has clear documentation, tests in the repository, a recent release, and organizational backing. Its name strongly resembles the much more established spatie/laravel-data, creating a serious risk that consumers may choose the wrong package; repository activity has also been inactive for three months.
45%
Total Score
83
100
83
83
The package name is flagged as resembling the far more established spatie/laravel-data, and borrows its identity despite low artifact overlap and no declared fork relationship. Consumers may most likely have intended the lookalike package instead.
The repository recorded no commits and no active maintainers during the last three months. This is a meaningful maintenance warning, although the package has a recent stable release and longer-term release history.
The repository uses Composer build tooling, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All three workflows were analyzed with no untrusted checkouts, script injection, or audit findings. However, all eight action references are unpinned, which weakens build reproducibility; the absence of top-level permissions blocks is acceptable here because no risky trigger or write scope was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/sun Version ^1.1.1 | — | — |
illuminate/view Version ^11.0|^12.0|^13.0 | — | — |
livewire/livewire Version ^4.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.