Clear documentation, repository tests, MIT licensing, and organization backing support adoption. The modest dependency footprint and security tooling help, while the missing security policy and workflow hygiene reduce confidence.
71%
Total Score
67
100
100
50
No commits and no active maintainers were recorded in the last three months, which is a meaningful maintenance concern for a young package.
There were no new or closed issues or pull requests in the last month; together with the quiet commit period, this weakens evidence of ongoing maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.
All workflows were analyzed and no untrusted checkout or script-injection issue was found. However, three workflows grant top-level write access and one high-confidence audit found an ad hoc package install, creating mild workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/temporary-directory Version ^2.2.1 | — | — |
spatie/laravel-package-tools Version ^1.16.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.