Usable with caveats: it is a clearly backed, licensed package with tests, release notes, and sensible dependency tooling, but it is still very young and has had no commits or issue activity for about three months. Review its maintenance status before making it a core dependency.
62%
Total Score
63
100
88
60
There were no commits and no active maintainers during the last three months. For a package only about three months old, that is a meaningful abandonment risk despite the recent release history.
One of five workflows uses pull_request_target for Dependabot auto-merge, which can carry elevated workflow risk. No untrusted checkout or script-injection patterns were detected, partly offsetting the concern.
A post-autoload-dump lifecycle script runs during installation. This is a limited install-time behavior and is not by itself a severe health concern, but it warrants normal review of what the script executes.
The package is only about 3 months old and has two releases, with the latest arriving shortly after the first. That shows an initial release effort but provides little long-term maintenance history.
The repository has 14 open issues and three open pull requests, but no issues or pull requests were created, closed, or merged in the last month. This suggests unresolved work and limited recent responsiveness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.