The package has clear documentation, a license, regular releases, and an active repository. Its small ownership base, only two commits in three months, incomplete workflow audit, and six unpinned actions leave meaningful maintenance and build-transparency concerns.
68%
Total Score
50
100
88
100
The repository is owned by a user account, so the single-contributor activity and one registry maintainer do not benefit from visible organizational backing.
Six releases in about 6.5 months, all within the last 12 months, with a median interval of about 3.4 days, shows active early development. The short history limits evidence of long-term stability.
One contributor made all two commits in the last three months. Because the repository is owned by a user rather than an organization, there is little visible handoff capacity if that contributor stops.
Only two commits were recorded in the last three months, showing some recent activity but a limited maintenance cadence for a young package.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.