Usable with caveats: the package is actively released, licensed, documented, tested in its repository, and backed by an organization. Recent repository activity is very light and concentrated in one contributor, while several workflows use broad or unspecified token permissions and no security policy is published.
74%
Total Score
70
100
94
60
Six workflows were analyzed with no untrusted checkouts or script injection, but one pull_request_target workflow exists for automated Dependabot merging and deserves review because that trigger can expose elevated repository context.
A post-autoload-dump install script runs during Composer installation. This is a legitimate but potentially consequential install-time behavior, so it adds a small supply-chain transparency concern.
All one recent commit came from a single contributor, leaving no demonstrated contributor redundancy. Organization backing reduces the operational concern somewhat but does not show that a second maintainer is active.
Only one commit was recorded in the last three months from one active maintainer, indicating very light recent development despite the strong registry release history.
There are no open issues and three open pull requests, but no issues or pull requests were newly created or merged in the last month. This gives little evidence of responsive public collaboration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
backstage/fields Version self.version | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
backstage/filament-uploadcare-field Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.