The repository includes tests, a changelog, and clear MIT licensing. Keep the workflow permissions and unpinned actions under review, since one contributor currently carries all 13 recent commits.
68%
Total Score
67
100
94
50
A post-autoload-dump install-time script runs during dependency installation. Without evidence of harmful behavior, this is a modest supply-chain caution rather than a severe risk.
The repository is owned by a user account rather than an organization, so there is no organizational maintenance capacity to offset the concentrated contributor base. The linked repository still appears relevant because its README mentions the package.
The package was first released today and has four releases in roughly 11 hours, so there is not yet a meaningful maintenance track record. The rapid initial releases provide activity but do not establish long-term stability.
One contributor made all 13 commits in the last three months, leaving no demonstrated backup maintainer. The individual-owned project backing does not compensate for this concentration.
No repository security policy was found. This is a minor transparency gap for a package that processes personal data, though it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/ai Version ^1.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
agentile/php-stanford-nlp Version ^0.1.1 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.