Documentation, tests, release notes, and a clear license reduce integration friction. Maintenance has paused recently, and the GitHub workflows leave all five action references unpinned, so pinning this version deserves care.
68%
Total Score
75
100
100
100
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern. The active release history and version-specific release notes provide some evidence of recent publishing, but do not replace ongoing source activity.
All three workflows were analyzed with no detected untrusted checkouts, script injection, or audit findings, but all five action references are unpinned and one workflow grants top-level write access. The broad token scope is only a mild concern here, while unpinned actions weaken build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/contracts Version ^11.28|^12.0 | — | — |
spatie/laravel-settings Version ^3.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.