Package Health

beranidigital/filament-access

Organization backing, a matching repository, licensing, tests, and security tooling provide useful safeguards. The package also runs a post-autoload-dump script, while its workflows use broad permissions and unpinned actions.

Latest 0.3PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump lifecycle script during Composer installation, adding executable install-time behavior that consumers should understand.

Release historycaution

The package is about 812 days old but has only four releases and one release in the last 12 months, indicating a thin release cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may currently be paused.

Version stabilitycaution

Version 0.3 is not a stable major release, so compatibility expectations are lower even though it is not marked as a prerelease.

Workflow auditcaution

All five workflows were analyzed, but all 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects Dependabot auto-merge. No untrusted checkout or script-injection sink was found, so this is a hygiene and workflow-control concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yusuf Sekhan Althaf

Direct Dependencies

DependencyLast ReleaseScore
nikic/php-parser
Version ^5.0
—
—
filament/filament
Version ^3.0
—
—
spatie/laravel-package-tools
Version ^1.15.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform