Usable with caveats: it is actively published, licensed, and backed by a repository with tests, but it is a young package maintained by one contributor. The lack of security tooling and policy, along with rapid early releases, warrants review before adopting it for critical use.
68%
Total Score
60
100
78
80
A post-autoload-dump install-time script is present, which adds some installation complexity and should be reviewed, but this signal alone is not a severe dependency risk.
Only one registry account has publish access, limiting publishing redundancy; the linked repository is also owned by an individual rather than an organization.
The repository is owned by a User account rather than an organization, so there is no organizational backing to offset the small maintainer base.
The package is only 114 days old but has 12 releases, with the latest published very recently; this shows active iteration, though the short history provides limited evidence of long-term stability.
One contributor made all two commits in the last three months, creating a concentrated maintenance risk with no second active contributor to provide resilience.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.