Its documentation, licensing, and release notes are clear, and the repository includes tests and a security policy. The main limitation is that one person made all recent commits, so continuity depends heavily on that maintainer.
84%
Total Score
63
100
100
100
Only one registry account has publish access. That is a continuity concern, although repository activity shows the same maintainer is actively developing the project.
The package and repository are owned by the same individual account. This is consistent ownership, but it does not provide organizational handoff capacity.
One contributor made all 45 recent commits, creating a high single-maintainer continuity risk; the recent commit volume partly compensates but does not remove that dependence.
All four workflows were analyzed successfully, all 11 action references are pinned, and no audit findings or untrusted execution paths were detected. Two workflows grant top-level write permissions, which is a mild hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
spatie/laravel-event-sourcing Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.