Clear documentation, repository tests, and an MIT license support adoption. The project has no commits or releases for about 19 months, while its workflow uses two unpinned actions and the repository lacks a security policy.
57%
Total Score
50
100
86
50
The repository recorded 0 commits and 0 active maintainers in the last 3 months, and its last push was about 19 months ago. That is the clearest abandonment concern in the available evidence.
The package has had 3 releases, all on 2025-02-25, with no releases in the last 12 months. This indicates a small and currently inactive release history, though it is not deprecated.
Composer is used for the build, but no security scanning tools are configured. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy. This weakens the documented process for reporting and handling vulnerabilities, although it does not by itself indicate abandonment.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, both action references are unpinned, leaving a minor reproducibility and workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.