The repository has a README, repository tests, and an MIT license. Maintenance stopped after four releases in two days, and a high-confidence audit found unpinned workflow images.
61%
Total Score
50
90
50
The package has four releases, all clustered within two days, with no later release during its roughly five-month history. That leaves limited evidence of sustained maintenance for a young package.
The repository recorded zero commits and zero active maintainers over the last three months, indicating that current maintenance activity has stalled.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. The package is otherwise linked to a matching repository with tests and a license.
Both workflows were analyzed successfully and have no untrusted checkout or script-injection findings, but all four analyzed references are unpinned and the auditor found a high-confidence unpinned container image.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.