The package includes tests, a changelog, a clear README, and an MIT license, with an active organization behind the repository. Recent release activity is strong, but no commits were recorded in the past three months and all 16 workflow actions are unpinned.
65%
Total Score
67
100
100
75
A post-autoload-dump install-time script is present. This is a supply-chain and installation-behavior consideration, though the signal does not show that it is unsafe.
No commits and no active maintainers were recorded during the past three months. The recent repository push and release history partly offset this, but the short-term maintenance pause remains a concern.
There are four open pull requests but no issues or pull requests were opened or merged in the past month, suggesting limited recent repository activity.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or audit failures. However, all 16 action references are unpinned, leaving build inputs less reproducible and more exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/db-dumper Version ^3.4 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/database Version ^10.0|^11.0|^12.0|^13.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.