Testing, a clear license, release notes, and a security policy add useful confidence. Workflow permissions and unpinned actions leave avoidable maintenance and build-hygiene concerns.
66%
Total Score
50
94
100
The package has 32 releases over about three and a half years, but none in the last 12 months; this suggests maintenance has slowed despite a previously active release cadence.
The repository recorded zero commits from maintainers during the last three months, which reinforces the concern that current maintenance has paused.
All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding was reported. The audit found no untrusted checkout or script-injection sink, so this is workflow hygiene risk rather than a severe dependency blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | — | — |
spatie/laravel-package-tools Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.