Clear documentation, source tests, licensing, and a security policy make integration transparent. The dependency scope is small and the workflows are fully audited, but long-term maintenance remains unproven.
62%
Total Score
50
100
92
83
A post-autoload-dump install lifecycle script runs during Composer installation. This is a modest supply-chain and installation-complexity concern, though the signal does not show harmful behavior.
The linked repository is owned by an individual account rather than an organization, so there is no demonstrated organizational capacity to offset the single-contributor activity.
The package is less than one day old, with five releases published within roughly 15 hours. This shows active initial iteration but provides no meaningful long-term maintenance history.
All observed recent commits come from one contributor, giving the project a bus factor of one. No organizational backing is shown to compensate for that concentration.
Only one commit and one active maintainer were observed over the last three months. Because the repository is newly created, this is evidence of limited maintenance capacity rather than established abandonment, but it leaves future support uncertain.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.