Documentation and project structure are strong, with repository tests, a changelog, and a security policy. Automation has all five actions unpinned and a high-confidence bot-condition finding, while commit activity has been absent for three months.
64%
Total Score
50
100
100
83
The package runs a post-autoload-dump lifecycle script during installation. This is an additional execution surface, though the signal gives no evidence that the script is unsafe.
The repository is owned by an individual account rather than an organization, so the single-publisher setup offers limited visible organizational backing for continuity.
The repository recorded zero commits and zero active maintainers in the last three months. That recent pause is a meaningful maintenance concern, although the repository was pushed in June 2026 and the package released version 1.2.4 in December 2025.
There are no open issues and three open pull requests. The lack of recently merged pull requests limits evidence of active review, but does not by itself show abandonment.
All three workflows were analyzed, but all five action references are unpinned and one workflow has top-level write permissions. The high-confidence bot-conditions finding in the Dependabot auto-merge workflow adds a concrete automation concern, while its pull_request_target trigger has no untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 || ^4.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.