Build structured navigation menus in Filament.
82%
Total Score
83
100
89
80
One workflow uses pull_request_target for Dependabot auto-merge, which warrants review because it can run with elevated repository context; no untrusted checkout or script-injection patterns were detected.
Two registry maintainers provide some publishing redundancy. The linked project is user-owned rather than organization-backed, so the small maintainer base remains a modest continuity consideration.
There have been 12 releases in about 233 days, showing ongoing publication, but the median interval is only about 15 minutes, suggesting unusually compressed release bursts rather than a clearly measured cadence.
The repository has zero stars, forks, and watchers. This limits independent evidence of adoption and review, although popularity is supporting evidence rather than a requirement for a small maintained package.
Four of five workflows omit top-level token permissions, and the Dependabot auto-merge workflow has top-level write access. Explicit least-privilege permissions would improve workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.