Documentation, licensing, and release cadence provide a solid foundation. Maintenance has recently slowed to one commit in three months, while the workflow audit found a high-confidence bot-condition issue and all 12 actions are unpinned.
63%
Total Score
50
100
100
100
The repository and registry package are owned by the same individual account, which supports package identity but provides no organizational backing to offset the concentrated contributor base.
One contributor made 100% of the single commit in the last three months. Because the owner is an individual rather than an organization, this leaves little demonstrated maintenance redundancy.
Only one commit was recorded in the last three months, which is thin activity for a package that released recently and raises a maintenance-continuity concern.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, plus all 12 action references are unpinned and three workflows grant top-level write permissions. No untrusted checkout or script-injection sink was found, but the automation still needs tightening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/shiki-php Version ^2.0 | — | — |
filament/filament Version ^4.5|^5.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
filament/spatie-laravel-media-library-plugin Version ^v4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.