The package is well documented, has repository tests, and is backed by an organization. Maintenance has gone quiet for about 16 months, while all 8 workflow actions are unpinned and no security policy is present.
54%
Total Score
50
75
50
Only 2 releases exist, both published about 16 months ago, with no release in the last 12 months. This is meaningful evidence of stalled maintenance for a package still at version 0.1.1.
The repository recorded 0 commits and 0 active maintainers during the last 3 months, consistent with the longer release gap and increasing abandonment risk.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented. The repository's tests and build tooling provide some quality structure but do not replace this policy.
Version 0.1.1 is not a stable major release, which limits maturity evidence, although it is not marked as a prerelease.
The audit completed cleanly with no high-confidence findings or untrusted checkouts, but all 8 action references are unpinned and one workflow grants top-level write access. These are workflow hygiene and maintenance risks, not severe risks on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.2 | — | — |
illuminate/contracts Version ^10.0||^11.0 | — | — |
borah/llm-port-laravel Version ^1.0.4 | — | — |
flowframe/laravel-trend Version ^0.3.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.