Clear documentation and project hygiene improve transparency, with tests, release notes, licensing, and dependency scanning visible. Workflow pinning and a missing security policy leave modest CI and disclosure safeguards to review.
86%
Total Score
100
100
100
50
A post-autoload-dump install-time script is present. The signal does not show that it is unsafe, but lifecycle execution adds a small amount of installation complexity.
No SECURITY.md or other security policy was detected, leaving vulnerability-reporting and disclosure expectations undocumented.
All five workflows were analyzed, but all 13 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence low-severity audit found ad hoc package installation. The pull_request_target workflow has no untrusted checkout or script-injection sink, so these are hygiene concerns rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/temporary-directory Version ^2.2.1 | — | — |
spatie/laravel-package-tools Version ^1.16.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.