Healthy and suitable to depend on, with a small maintenance caveat. It has a decade of history, regular releases, clear ownership, tests, documentation, and a matching source repository, but no commits were recorded in the last three months.
78%
Total Score
88
100
100
70
One workflow uses pull_request_target for Dependabot auto-merge, which warrants care because that trigger can grant elevated repository context, but no untrusted checkouts or script-injection patterns were detected.
No commits or active maintainers were recorded in the last three months, which is a maintenance concern; the recent repository push and four releases in the past year partly compensate for this pause.
No repository security policy was found, leaving vulnerability reporting guidance less transparent for users and maintainers.
Three workflows omit top-level token permissions and two declare top-level write access, indicating weaker-than-ideal least-privilege workflow configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.93.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.