The package is clearly documented, licensed, and backed by repository tests. Two recent commits came from two active contributors, while the low release count over the past year and absent security tooling leave modest maintenance uncertainty.
76%
Total Score
100
79
50
The post-autoload-dump install-time script adds a supply-chain execution surface. A single Composer lifecycle hook is a limited concern rather than a severe risk on its own.
The package has 18 releases over about 662 days and a short historical median interval, but only 2 releases in the last 12 months; this indicates slower recent maintenance without showing abandonment.
Composer build tooling is present, but no security-scanning tool was detected. That leaves a modest transparency and maintenance gap, though it does not establish unsafe behavior.
The repository has no security policy, so users have no documented vulnerability-reporting path. This is a transparency gap, but it is not evidence that the release is unsafe.
Version 0.4.0 is a stable release rather than a prerelease, but the pre-1.0 major version signals that compatibility and API maturity may still be evolving.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 || ^4.0 || ^5.0 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.