The MIT license, complete README, release notes, tests in the repository, and organization backing provide useful transparency. Maintenance has slowed, while workflow permissions, unpinned actions, and a high-confidence bot-condition warning add adoption risk.
60%
Total Score
75
90
50
The package has 31 releases but none in the last 12 months; its latest release was about 18 months ago. Earlier release history shows maturity, but the recent pause raises maintenance risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is a meaningful sign of currently limited maintenance capacity.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, though Dependabot provides some compensating security tooling.
All 4 analyzed action references are unpinned, both workflows grant top-level write access, and a high-confidence bot-conditions finding warns that actor context may be spoofable. The pull_request_target workflow has no untrusted checkout or script-injection findings, so this is a hygiene and workflow-integrity concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^4.27 | — | — |
intervention/image Version ^3.0 | — | — |
illuminate/contracts Version ^10.0 | ^11.0 | — | — |
creode/laravel-assets Version ^1.4 | ^2.0 | — | — |
creode/permissions-seeder Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.