Usable with caveats: it is actively releasing, documented, tested in the repository, and not deprecated or archived. The project is only 52 days old and all recent commits come from one contributor, while permissive CI workflows and an install-time script add maintenance and supply-chain exposure.
68%
Total Score
67
94
50
One of three workflows uses pull_request_target, a sensitive trigger, although no untrusted checkout or script injection was detected.
The package runs a post-autoload-dump install-time script, which increases installation complexity and deserves review before adoption, even though the signal does not show malicious behavior.
The repository is owned by an individual rather than an organization, so the single-maintainer and bus-factor concerns are not compensated by visible organizational backing.
All 8 recent commits came from one contributor, creating a clear single-maintainer continuity risk with no demonstrated backup contributor.
The repository has no security policy, leaving vulnerability-reporting and response expectations unspecified.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.