Usable with caveats: it is a very new v0.1.1 package with no demonstrated commit history yet, so long-term maintenance is unproven. It is backed by a matching repository with tests, release notes, security tooling, and no deprecation or archive warning.
72%
Total Score
75
89
80
The package runs a post-autoload-dump install-time script, which adds execution during installation and warrants review, but a single Composer lifecycle script is not by itself evidence that the package is unsafe to depend on.
Only one registry publishing account is listed, limiting visible publishing redundancy. However, the repository is organization-owned, making a short registry maintainer list normal publishing hygiene rather than strong abandonment evidence.
The package is brand new, with two releases over roughly 22 minutes and no longer-term release record. This limits evidence of sustained maintenance, though the rapid initial releases are not themselves a severe concern.
There have been no commits from active maintainers in the last three months, so sustained maintenance cannot yet be demonstrated. Because the package itself is only hours old, this is an evidence gap rather than proof of abandonment.
All workflows declare permissions, and three are read-only, but two workflows request top-level write access. This is a modest CI privilege concern without the more severe workflow hazards identified elsewhere.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.