Usable with caveats: the package is licensed, clearly backed by a matching repository, and has repository tests and release tooling. Adoption carries maintenance risk because it has only two releases over 437 days and no commits or active maintainers in the last three months, with additional workflow-permission concerns.
68%
Total Score
50
100
89
60
One of five workflows uses pull_request_target for Dependabot auto-merge, which carries elevated workflow trust risk, although no untrusted checkout or script-injection pattern was detected.
A post-autoload-dump script runs during installation, adding some install-time behavior that should be reviewed, but the signal does not show a severe or clearly unsafe action.
Two registry publishing maintainers provide some release redundancy, but the zero active repository maintainers in the last three months shows that registry access does not demonstrate ongoing development.
The registry namespace and repository are owned by the same individual account, so the project has direct ownership alignment but no organization-level backing shown by this signal.
Only two releases have been published across 437 days, with one release in the last 12 months, indicating a thin release history and limited evidence of sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mailer Version ^6.0|^7.0 | — | — |
illuminate/contracts Version ^9.38|^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.