The MIT license, matching repository, and clear README make the package transparent to inspect. However, its single-release history, v0.1.0 status, absent tests, and lack of a security policy leave maintenance and reliability unproven.
62%
Total Score
75
100
79
50
The package runs a post-autoload-dump install-time script. This is not inherently unsafe, but it adds execution during installation and deserves more scrutiny in a package with little maintenance history.
The repository is owned by an individual account rather than an organization, so the package has limited visible institutional backing.
This is the package's first release, published 0 days ago, so there is no release history or cadence demonstrating sustained maintenance.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and hygiene gap for a newly published package.
The linked repository has no security policy, leaving vulnerability-reporting expectations unspecified. This matters more for a package intended to run inside Laravel applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.