The project has clear ownership, a matching repository, tests, release notes, and a current stable release. However, the package identity signal strongly suggests it borrows another package's identity, making adoption risky despite otherwise solid maintenance evidence.
45%
Total Score
83
100
85
75
The signal marks this package as borrowing the identity of spatie/backtrace, with explicit identity borrowing despite zero artifact overlap and no README claim of being a fork. Consumers may have intended the lookalike package instead.
The repository recorded no commits and no active maintainers in the last three months, which is a maintenance concern, although the package had a release during the assessed period.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no published security policy, reducing transparency about vulnerability reporting and response.
All four workflows were analyzed with no audit findings or untrusted checkouts, but all 11 action references are unpinned and one workflow grants top-level write permissions. These are meaningful workflow hygiene concerns without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.68.1|^3.0 | — | — |
spatie/macroable Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.