The package has a clear license, documentation, repository tests, and regular recent development. Its GitHub automation has a high-confidence bot-condition issue and all six actions are unpinned, so release automation deserves extra care.
68%
Total Score
100
100
94
67
All six action references are unpinned, and a high-confidence, high-severity bot-conditions finding reports spoofable actor context in the Dependabot auto-merge workflow. Two workflows also grant top-level write access; the pull_request_target trigger has no untrusted checkout or script-injection sink shown.
The package runs a post-autoload-dump install-time script. This is a meaningful execution surface, but the signal provides no evidence that the script is unsafe.
The repository has no stars and one fork. This is weak supporting evidence, but popularity is not required for a small, actively maintained package.
The repository has no security policy. That reduces vulnerability-reporting transparency, although Dependabot and active repository maintenance partly offset the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.