Package Health

c6digital/filament-passwordless-login

This release appears generally suitable to depend on: it is a stable v2.0.0 release from a package that has existed for about 2 years and 9 months, is not deprecated, has a matching organization-owned repository, and includes clear licensing, changelog, security-policy, CI, and repository test evidence. The main concerns are modest maintenance depth—only 6 releases overall, 2 in the last 12 months, and no commits or active maintainers in the last 3 months—and workflow permission hygiene, including write-capable workflows and one pull_request_target workflow. These warrant monitoring, but the repository was recently pushed and the package is not archived, so the evidence does not indicate abandonment or an unfit dependency.

Latest v2.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

Five workflows were analyzed with no untrusted checkouts or script-injection findings, but one pull_request_target workflow is used for Dependabot auto-merge and therefore deserves review because that trigger has elevated workflow risk.

Lifecycle scriptscaution

A post-autoload-dump install lifecycle script is present. This is a potentially consequential install-time behavior, but the signal provides no evidence that it performs unsafe or unusual actions.

Release historycaution

The package has been published for about 2 years and 9 months with 6 releases and 2 releases in the last 12 months; this shows ongoing release activity but a relatively small release history.

Repo commit activitycaution

There were 0 commits and 0 active maintainers during the last 3 months, indicating a recent pause in development. The recent repository push and latest release partially mitigate abandonment concerns but do not remove the maintenance caution.

Repo popularitycaution

The repository has 8 stars, 3 forks, and 0 watchers. This indicates limited adoption and support visibility, though popularity is only supporting evidence and does not by itself make a small maintained package unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ryan Chandler

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.0 | ^5.0
—
—
illuminate/contracts
Version ^11.28 | ^12.0 | ^13.0
—
—
spatie/laravel-package-tools
Version ^1.15.0
—
—
danharrin/livewire-rate-limiting
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform