The package includes a clear README, tests, and a matching source repository. No commits were recorded in the last three months, and all five workflow actions are unpinned, so maintenance and build reproducibility need attention.
70%
Total Score
50
100
94
67
A post-autoload-dump install-time script runs during Composer installation. This is a mild operational consideration, but the signal alone does not show harmful or unusually broad behavior.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization. This indicates direct ownership without the stronger continuity signal of organizational backing.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, though recent registry release activity provides some contrary evidence.
The repository uses Task and Composer build tooling, but no security-scanning tools were detected. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
Both workflows were fully analyzed with no audit findings, no untrusted checkouts, and no script injection. However, all five action references are unpinned, which weakens build reproducibility and leaves dependency updates uncontrolled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 || ^5.0 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.