Documentation, licensing, repository tests, and recent commits support continued maintenance. The project is small and lacks a security policy, while its release-version metadata is inconsistent and workflow hygiene needs attention.
72%
Total Score
75
100
94
50
One registry publishing account is a limited publishing base, but repository activity shows two active contributors recently, partly offsetting the registry concentration.
The repository is owned by an individual rather than an organization, so the small maintainer base has less institutional backing to absorb maintainer absence.
No security policy was found. This is a transparency gap for reporting vulnerabilities, although it does not by itself indicate abandonment.
This release is marked stable and not a prerelease, but the reported latest version is v1.0.1 while the assessed release is v2.2.0. That inconsistency reduces transparency in the collected registry metadata.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow and all 12 analyzed action references are unpinned. Three workflows also grant top-level write permissions; without an untrusted checkout or script-injection sink, these are workflow-hygiene concerns rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^4.0||^5.0 | — | — |
filament/support Version ^4.0||^5.0 | — | — |
illuminate/contracts Version ^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.