Usable with caveats: the package is established, actively released, clearly backed by Spatie, and has solid repository and packaging hygiene. However, no commits were recorded in the last three months, and the repository lacks a security policy while several workflows omit explicit token permissions.
72%
Total Score
83
100
100
70
One workflow uses pull_request_target for Dependabot auto-merge, which carries elevated workflow risk. No untrusted checkout or script-injection patterns were detected, limiting the concern.
No commits or active maintainers were recorded during the last three months, despite the strong longer-term release history. This is a meaningful short-term maintenance concern, though it is not evidence of abandonment by itself.
The repository has no security policy. That weakens vulnerability-reporting transparency for a package used in application debugging, although other repository security tooling is present.
Four of five workflows lack top-level token permissions, and the auto-merge workflow has top-level write access. This is weaker least-privilege hygiene, although no other workflow-risk indicators show untrusted checkout or script injection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.0|^4.1 | — | — |
spatie/backtrace Version ^1.7.1 | — | — |
spatie/macroable Version ^1.0|^2.0 | — | — |
symfony/stopwatch Version ^4.2|^5.1|^6.0|^7.0|^8.0 | — | — |
symfony/var-dumper Version ^4.2|^5.1|^6.0|^7.0.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.