Documentation, licensing, and security scanning are in place. However, this is the only registry release, with no commits in the last three months, and its Dependabot auto-merge workflow has a high-confidence bot-condition finding.
52%
Total Score
50
88
75
The package runs a post-autoload-dump lifecycle script during Composer installation. This is worth noting because install-time code executes automatically, but the signal alone does not show harmful behavior.
This is the package's only release, published about 19 months ago, with no releases in the last 12 months. That leaves little evidence of sustained registry maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this raises a meaningful risk of stalled maintenance.
The assessed version is v0.1.0 and is not marked as a prerelease, but it remains an early major version with only one release, limiting maturity evidence.
All three workflows were analyzed, but all six action references are unpinned and two workflows grant top-level write permissions. The high-confidence bot-conditions finding in the Dependabot auto-merge workflow is a further workflow-hygiene concern, although no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.2 | — | — |
ralphjsmit/laravel-seo Version ^1.6 | — | — |
ariaieboy/filament-currency Version ^1.10 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
ralphjsmit/laravel-filament-seo Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.