The project has a clear license, tests in its repository, release notes, and a matching source repository. Maintenance is concentrated in one person, releases are roughly a year apart, and workflow references are not pinned.
67%
Total Score
50
100
88
75
Only one account has registry publishing access. That is consistent with the repository being user-owned, but it leaves little publishing redundancy.
The repository is owned by an individual rather than an organization, so the concentrated maintainer and contributor activity is not offset by visible organizational handoff capacity.
The package has existed for about 3 years and has four releases, but only one release in the last 12 months and a median interval of roughly 12 months indicate a slow maintenance cadence.
One contributor made all recent commits, giving the project a bus factor of one and increasing the risk that maintenance stops if that person becomes unavailable.
Only one commit was recorded in the last 3 months, showing some recent activity but a very limited maintenance volume.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.