The repository includes tests and has two active contributors, which helps offset its short history. There is no security policy, so maintenance transparency remains limited.
68%
Total Score
75
100
94
50
The package is only 50 days old, with all three releases published within roughly 42 minutes. That shows initial activity but provides little evidence of sustained maintenance yet.
Two contributors are active, but the leading contributor made 7 of 9 recent commits. That concentration leaves maintenance capacity somewhat dependent on one person.
The repository has no SECURITY.md or other declared security policy. This limits transparency for reporting and handling security issues.
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The pull_request_target workflow has no untrusted checkout or script-injection finding, so this is workflow hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.