Clear licensing, repository tests, and release notes make the package straightforward to inspect. Pin this exact version and check future releases before upgrading.
61%
Total Score
75
100
86
100
The package is over three years old but has only five releases, with a median interval of about 344 days and one release in the last 12 months. This indicates a slow maintenance cadence, though v0.1.4 was released recently.
The repository recorded zero commits and zero active maintainers during the last three months. Although a recent release exists, the lack of current development activity is a meaningful abandonment warning.
The release is not marked prerelease, but the package remains below a stable major version at v0.1.4. That increases the chance of compatibility changes compared with a mature 1.x package.
All three workflows were analyzed, but all nine action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is workflow hygiene risk rather than a severe release risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.