This is a usable, licensed package with a stable major release, 13 releases over roughly 20 months, recent publication activity, a matching repository, documented usage, and repository tests and changelog coverage. The main concerns are that the repository recorded no commits or active maintainers in the last 3 months despite a recent push and release, the project is backed by a single individual, security scanning and a security policy are absent, and the workflow does not declare top-level token permissions. Its small popularity footprint is not disqualifying for a focused Laravel package, but adoption should account for the thin maintenance and security-reporting posture.
72%
Total Score
50
50
89
70
Five runtime dependencies, including Laravel, Filament, and Spatie model states, are material coupling for a focused integration package. The dependency set is understandable from the package description but increases compatibility and upgrade surface.
A post-autoload-dump lifecycle script is present. This adds install-time execution surface, but the signal does not indicate a dangerous script or explain behavior severe enough to make the package unfit.
Only one registry account has publish access. That is a genuine continuity risk for an individually backed package because release capacity may depend on one person.
The repository is owned by a User account rather than an organization, so there is no organizational backing signal to compensate for the single-maintainer model.
The repository recorded zero commits and zero active maintainers over the last 3 months. Although a recent push and current release show some activity, the absence of recent commit activity weakens confidence in ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0||^5.0 | — | — |
illuminate/contracts Version ^13.0||^10.0||^11.0||^12.0 | — | — |
spatie/laravel-model-states Version ^2.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.