The package is licensed and documented, with repository tests, release notes, and Dependabot coverage. One maintainer, only two releases on the same day, and no commits in three months leave limited evidence of sustained maintenance; workflow permissions and unpinned actions also need care.
56%
Total Score
50
100
94
67
The package uses a post-autoload-dump install-time script. This is a real execution step during installation, though the signal provides no evidence that it is unsafe.
A single registry maintainer creates a thin publishing base, although the linked project is owned by the same individual and the package is small.
The repository is owned by an individual rather than an organization, so the project does not show organizational backing to offset its single-maintainer structure.
The package is 233 days old but has only two releases, both published on the same day, so its maintenance track record is still limited.
The repository recorded zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.