The dependency scope is small and the repository is not archived or deprecated. Documentation and testing coverage are thin, and the sole registry maintainer is supported by an organization; one workflow action is unpinned.
58%
Total Score
67
100
72
63
Only one account has registry publish access, which is a concentration risk. The repository owner is an organization, providing some backing that partly offsets the thin registry maintainer base.
The repository contains only 12 files, mostly source files and package metadata, with no visible tests or documentation. That compact structure may be intentional, but it provides limited evidence of project maturity.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer transparency for a Laravel package.
The package has had no release in the last 12 months, with the latest release over one year ago. Its seven releases were concentrated early, which weakens evidence of ongoing maintenance.
There are no open issues or pull requests and no recent activity. This is not inherently negative for a small package, but it provides little evidence of an active user or contributor community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.