This release appears healthy and reasonably safe to depend on: it is licensed, actively released, stable, non-deprecated, backed by a matching repository, and has recent commit and issue activity from two contributors. The package includes substantial documentation, a changelog, build scaffolding, and tests indicated across the artifact and repository. The main reservations are the small contributor base, absence of a security policy and security scanning, and workflows that grant top-level write permissions; these are meaningful supply-chain hygiene gaps but are not outweighed by evidence of abandonment or repository mismatch.
80%
Total Score
70
100
94
80
Only one account has registry publish access, which is a modest publishing continuity concern for an individually owned project. However, registry access reflects administrative permissions rather than actual maintenance, and repository activity shows a second active contributor.
The repository is owned by an individual user rather than an organization, so there is no organizational handoff assurance. This is moderated by recent releases and activity from two contributors.
Two contributors were active, but the leading contributor made 75% of recent commits. The second contributor remains active, partially mitigating concentration, though the small contributor base still creates some continuity risk.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a genuine security-hygiene gap, though it is not evidence of maliciousness or abandonment by itself.
The repository has no security policy. This reduces vulnerability-reporting transparency and response expectations, creating a maintenance and security-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0|^4.1 | — | — |
livewire/livewire Version ^4.0|^3.0 | — | — |
illuminate/contracts Version ^13.0|^12.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.