The repository has had no commits from active maintainers in the last three months, and every GitHub Action reference is unpinned. A high-confidence workflow check also found a potentially spoofable bot condition, although releases, tests, licensing, and security documentation provide useful support.
55%
Total Score
50
100
83
83
The package is young at 204 days, with 8 releases and a median interval of about 2 days, showing active early development but limited long-term history.
The repository recorded 0 commits and 0 active maintainers in the last three months, a meaningful sign of slowing maintenance for a young package.
Version 0.4.2 is not a stable major release, so compatibility and API changes remain more likely than for a mature 1.x package.
All 12 action references are unpinned, and a high-confidence audit found a potentially spoofable bot condition in the Dependabot auto-merge workflow. The audit was complete, but these workflow weaknesses reduce supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
league/commonmark Version ^2.7 | — | — |
nette/php-generator Version ^4.2 | — | — |
pboivin/filament-peek Version ^4.0 | — | — |
ralphjsmit/laravel-seo Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.