Usable with caveats: the package is clearly backed by a matching organization repository with tests, documentation, and security tooling, but it has only two releases and no recorded commits in the last three months. Its pre-1.0 status and long registry release gap make future compatibility and maintenance less certain.
62%
Total Score
83
100
88
90
Only two releases have been published since January 2022, with no release in the last 12 months and a median interval of about 853 days. This is a meaningful maintenance and update-risk concern.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the sparse release history, this is the main evidence of uncertain ongoing maintenance.
The test workflow does not declare top-level token permissions. No write permissions are explicitly requested, but the missing restriction is a minor workflow-hygiene gap.
Version v0.2.0 is not a prerelease, but the package remains below major version 1, so compatibility guarantees are weaker than for a mature stable-major package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.6 | — | — |
illuminate/contracts Version ^8.0|^9.0|^10.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.