Package Health

ghanem/rating-filament

Healthy and usable for adoption, with a young but active project behind it. The main caveat is that all recent repository work comes from one contributor, while the repository lacks explicit top-level workflow permissions.

Latest v1.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. That is a limited publishing base, although the repository is owned by an organization, which provides some backing beyond the registry account.

Release historycaution

The package is young at 45 days old with three releases and a median interval of about 11 days. That shows early activity, but the short history leaves long-term maintenance unproven.

Repo bus factorcaution

All 22 commits in the last three months came from one contributor, creating a real continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.

Token permissionscaution

The only workflow lacks a top-level permissions declaration. No write permissions were observed, but explicitly declaring least-privilege permissions would make the workflow's security posture clearer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

abdullah ghanem

Direct Dependencies

DependencyLast ReleaseScore
ghanem/rating
Version ^2.1
—
—
filament/filament
Version ^4.0|^5.0
—
—
illuminate/support
Version ^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform