The project has current release activity, thorough documentation, tests, and a security policy. Recent repository commits are absent, and all five workflow action references are unpinned, leaving maintenance and build reproducibility concerns.
68%
Total Score
83
100
89
83
A post-autoload-dump script runs during installation. This is a mild operational consideration, but the signal alone does not show harmful or unusual behavior.
The repository has recorded zero commits and zero active maintainers in the last three months, despite the recent release. This creates a meaningful concern about current maintenance capacity.
The repository has one star and no forks, indicating limited external adoption. Popularity is supporting evidence only, so this mildly reduces confidence in community backing rather than making the package unfit.
Composer build tooling is present, but no security scanning tools are configured. The security policy and workflow audit partly compensate, though automated security coverage is limited.
Both workflows were analyzed successfully with no detected injection or high-confidence audit findings. However, all five action references are unpinned and one workflow grants top-level write permission, creating reproducibility and token-scope hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.