Healthy and reasonable to adopt, with a few supply-chain hygiene caveats. It has an organization-backed repository, recent commits from two contributors, tests, documentation, release notes, and a stable release, but only two releases so far and lacks a security policy with some workflows using broad or unspecified token permissions.
78%
Total Score
88
100
83
63
The package uses a post-autoload-dump install-time script. This is a point requiring review because lifecycle scripts execute during installation, although the signal does not show that the script is malicious or unusually broad.
The package is about 349 days old but has only two releases, with roughly 155 days between them. This is limited maturity evidence, though the latest release is recent and the repository remains active.
There is only one open issue and no recent issue or pull-request activity. This provides little evidence of community review, but it does not by itself show abandonment.
The repository has only two stars and two forks, so external adoption and review are limited. This is supporting evidence rather than a major concern for a small, otherwise documented package.
The project uses Make and Composer build tooling, but no security scanning tools were detected. The missing automated security checks reduce transparency somewhat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^11.0|^12.0 | — | — |
cviebrock/eloquent-sluggable Version ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.