The package includes a substantial README, repository tests, release notes, and active recent development. Its small maintainer base and workflow configuration leave meaningful continuity and automation risks.
62%
Total Score
75
88
33
All 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; three workflows also grant top-level write access. The pull_request_target workflow has no untrusted checkout or script-injection findings, which limits the severity.
A post-autoload-dump install script is present, which adds installation-time behavior and modest supply-chain exposure, but this alone is not evidence of unsafe or excessive behavior.
All 8 recent commits came from one contributor, leaving maintenance continuity dependent on a single person with no provided organizational backing.
Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and defensive-maintenance gap.
The repository has no security policy, so users are given no documented route for reporting vulnerabilities or understanding the project's security process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.