Usable with caveats: the release is licensed, documented, correctly backed by its repository, and has recent stable releases. Maintenance has paused over the last three months, and the workflows grant write access broadly, so review future updates before relying on it heavily.
72%
Total Score
75
100
100
80
One workflow uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can operate with elevated repository context; no untrusted checkout or script-injection findings were detected.
Only one account has registry publish access, which is a resilience concern, but the repository is owned by an organization, making a short registry maintainer list less concerning.
The repository recorded zero commits and zero active maintainers in the last three months, indicating a recent maintenance pause despite the recent release history and July push.
All three analyzed workflows declare top-level write permissions, which broadens the impact of a workflow compromise and is weaker than least-privilege configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/tables Version ^5.0 | — | — |
filament/support Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.93.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.