This release appears generally suitable to depend on: it is a stable v2.0.0 release from a package that has existed for about 2 years and 9 months, is not deprecated, has a matching organization-owned repository, and includes clear licensing, changelog, security-policy, CI, and repository test evidence. The main concerns are modest maintenance depth—only 6 releases overall, 2 in the last 12 months, and no commits or active maintainers in the last 3 months—and workflow permission hygiene, including write-capable workflows and one pull_request_target workflow. These warrant monitoring, but the repository was recently pushed and the package is not archived, so the evidence does not indicate abandonment or an unfit dependency.
78%
Total Score
88
100
89
70
Five workflows were analyzed with no untrusted checkouts or script-injection findings, but one pull_request_target workflow is used for Dependabot auto-merge and therefore deserves review because that trigger has elevated workflow risk.
A post-autoload-dump install lifecycle script is present. This is a potentially consequential install-time behavior, but the signal provides no evidence that it performs unsafe or unusual actions.
The package has been published for about 2 years and 9 months with 6 releases and 2 releases in the last 12 months; this shows ongoing release activity but a relatively small release history.
There were 0 commits and 0 active maintainers during the last 3 months, indicating a recent pause in development. The recent repository push and latest release partially mitigate abandonment concerns but do not remove the maintenance caution.
The repository has 8 stars, 3 forks, and 0 watchers. This indicates limited adoption and support visibility, though popularity is only supporting evidence and does not by itself make a small maintained package unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | ^5.0 | — | — |
illuminate/contracts Version ^11.28 | ^12.0 | ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
danharrin/livewire-rate-limiting Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.