The MIT license, matching repository, tests, and Dependabot provide useful transparency. However, the sole registry release is years old, repository commits have stopped, and one workflow has a high-confidence bot-condition issue with all actions unpinned.
42%
Total Score
33
79
33
The package has only one release, published over three years ago, with no releases in the last 12 months. This is strong evidence of a stagnant release process.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the old registry release, this is a substantial abandonment risk.
The audit analyzed all five workflows and found a high-confidence bot-conditions issue in a Dependabot auto-merge workflow. All 12 action references are unpinned, and one workflow grants top-level write permissions, increasing workflow supply-chain risk.
The package runs a post-autoload-dump lifecycle script during installation. This is a supply-chain exposure worth noting, though the signal does not show that the script is unsafe.
The repository is owned by an individual account rather than an organization, so the single maintainer represents a thin backing structure. This reinforces the maintenance risk but is not evidence of abandonment alone.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^9.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.