The package is small but clearly structured, licensed, and backed by a matching organization repository. Its workflows need tighter controls, including unpinned actions and a high-confidence bot-condition warning.
58%
Total Score
75
100
89
67
The package runs a post-autoload-dump install lifecycle script. This adds installation-time behavior that should be understood before adoption, although the signal does not show that it is unsafe.
Only three releases appeared on the registry, all within a brief period, followed by more than two years without a release. That substantially raises abandonment risk despite the stable 1.0.2 version.
There were no commits and no active maintainers in the last three months. Combined with the long registry release gap, this is a meaningful maintenance and abandonment concern.
There are three open pull requests but no new or merged pull requests in the last month. This suggests limited current project activity, though the small backlog is not itself severe.
The repository has no stars, forks, or watchers. This is weak supporting evidence, but popularity is not decisive for a small package with a matching source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fakerphp/faker Version ^1.23 | — | — |
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.