The package includes tests, a changelog, release notes, a license, and repository security tooling. Its single-maintainer base, inactive recent commits, and broadly writable workflows warrant caution for long-term use.
61%
Total Score
50
100
89
70
One workflow uses pull_request_target for Dependabot auto-merge, but no untrusted checkouts or script-injection patterns were detected; the configuration deserves review without being severe on its own.
A post-autoload-dump lifecycle script runs during installation, adding execution during dependency setup and a modest transparency concern.
Only one registry account has publish access, which creates limited release continuity if that maintainer becomes unavailable.
The repository is owned by an individual rather than an organization, so the single-maintainer publishing model is not backed by a broader ownership structure.
The package has 5 releases, but none in the last 12 months and its latest release was over 20 months ago, indicating a prolonged maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-permission Version ^6.9 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.