A PHP package that helps you display the version of your Laravel or vanilla PHP application by leveraging git version tags
67%
Total Score
50
100
89
75
A post-autoload-dump install-time script runs during Composer installation. The signal does not show that it is unsafe, but any install-time execution adds supply-chain exposure compared with a package without lifecycle scripts.
One registry account has publish access. The repository is owned by the same individual, so the small maintainer list reflects a single-person project rather than an unexplained publishing mismatch; it still indicates limited redundancy.
The repository is owned by an individual rather than an organization, so there is no visible organizational redundancy behind the single maintainer.
The repository recorded 0 commits and 0 active maintainers during the last 3 months. Although a release was published recently, the lack of recent source activity raises maintenance risk.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is only supporting evidence, but these very low adoption indicators provide little external validation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.