Package Health

chiiya/filament-access-control

Healthy and suitable to use, with a few workflow and maintenance caveats. The package has a long release history, a current stable release, clear repository ownership, security tooling, and recent release activity, but no commits or active maintainers were recorded in the last three months and some workflows use broad token permissions.

Latest 2.9.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Dangerous workflowscaution

One of three workflows uses pull_request_target, creating elevated workflow-risk potential, but no untrusted checkout or script-injection patterns were detected.

Project backingcaution

The registry namespace and repository owner are the same individual account, which provides direct ownership alignment. A single-user project has less organizational redundancy than an organization-backed project.

Repo commit activitycaution

No commits and no active maintainers were recorded during the last three months. This is a meaningful maintenance warning, although the recent 2.9.0 release and repository push provide compensating evidence that the project has not been abandoned.

Repo issue activitycaution

The repository has only one open issue and one open pull request, with no new or merged items in the last month. The low backlog is positive, but the absence of recent issue or pull-request movement offers little evidence of ongoing responsiveness.

Token permissionscaution

Two workflows omit top-level permissions and one declares top-level write access. These settings reduce workflow transparency and least-privilege assurance, though they do not by themselves show a malicious workflow.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Elisha Witte

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^5.3
—
—
illuminate/contracts
Version ^12.0|^13.0
—
—
spatie/laravel-permission
Version ^6.4|^7.2
—
—
spatie/laravel-package-tools
Version ^1.11
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform