The repository has two active contributors and three commits in the last three months, with organization backing. All four workflow actions are unpinned and no security policy is published, so maintenance is healthy but supply-chain hygiene is incomplete.
78%
Total Score
100
89
75
The repository has one star and no forks or watchers, so there is little community evidence to supplement the maintenance signals.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and hygiene gap.
The repository has no published security policy, which limits guidance for reporting and handling vulnerabilities.
All three workflows were analyzed successfully, use read-only permissions, and contain no audited findings; however, all four action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.