The package is well documented, licensed, and backed by a matching organization repository. Its release and commit activity have stopped, while workflows leave all actions unpinned and no security policy is provided.
40%
Total Score
75
83
67
The package borrows the identity of the much more established spatie/laravel-query-builder: borrows_lookalike_identity is true, despite zero artifact overlap. Consumers may have intended to install the lookalike package instead.
The package has 11 releases since August 2022, but none in the last 12 months; the latest release was on May 10, 2024. This indicates a meaningful maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months. Although the repository is not archived, current development activity is absent.
The linked repository has no security policy. This reduces transparency for reporting vulnerabilities, though Dependabot provides some compensating security tooling.
All 9 analyzed action references are unpinned, and one workflow grants top-level write permissions. The pull_request_target workflow has no untrusted checkout or script-injection sink, so this is workflow hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^10.0|^11.0 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.13.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.