This is a usable but very young package with good transparency and project structure: it has an MIT license, README and changelog, repository tests, a complete-looking 17-file artifact, matching source repository, and organization backing. It is not deprecated or archived, and its latest release was published recently. However, the 0.0.8 version indicates early-stage maturity, releases have been concentrated in a short period, repository commit activity shows no commits or active maintainers in the last 3 months, and the repository has no stars or forks. Missing security scanning and a security policy, along with broad or absent workflow token restrictions, add supply-chain hygiene concerns. Depend on it only with normal review and monitoring, especially because long-term maintenance is not yet demonstrated.
62%
Total Score
63
100
78
70
The package uses a post-autoload-dump install-time script. This is an operational consideration, but the signal does not show a dangerous workflow or otherwise make the package unfit on its own.
Only one registry account has publish access, which is a modest continuity risk, although the linked repository is owned by an organization and the maintainer count alone does not establish abandonment.
The package is only 240 days old with 8 releases, all within the last 12 months; the roughly 12-hour median release interval suggests a bursty early release history rather than demonstrated long-term stability.
The repository records 0 commits and 0 active maintainers over the last 3 months, despite a recent push and recent releases; this leaves ongoing maintenance capacity unproven and is the strongest health concern.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently unhealthy for a small package, but it also provides no evidence of an active user or maintainer feedback loop.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
inertiajs/inertia-laravel Version ^2.0||^3.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.