Clear documentation, release notes, and cross-database CI improve confidence. The project is very young, with all 14 recent commits from one contributor and no security policy; pinning a later release after more project history would be prudent.
68%
Total Score
67
100
83
67
The repository owner is an individual user rather than an organization, so the one-person contributor concentration is not compensated by visible organizational backing.
The package is only 91 days old and has two releases, both in the last 12 months. This provides limited evidence of long-term maintenance, despite the recent release activity.
One contributor made all 14 commits in the last three months, leaving no demonstrated backup maintainer and increasing continuity risk for this young project.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this weakens external validation but does not independently indicate poor health.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest process gap, partly offset by the repository's CI workflow.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.