Healthy and reasonable to adopt. It is actively maintained, has repository tests and security tooling, and is clearly backed by the matching source repository; the main caveats are its short 44-day history, small contributor base, and permissive workflow settings.
82%
Total Score
83
100
89
80
One of six workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can carry elevated workflow risk. No untrusted checkout or script-injection findings were detected.
The package is young at 44 days, with three releases and a median interval of about 22 days. That limits evidence of long-term stability, but the recent release cadence is active rather than stalled.
Two contributors were active, but the leading contributor made about 76% of recent commits. This is a modest concentration risk, partially offset by the second contributor's 13 commits.
The repository has only five stars and no forks or watchers, so there is little community adoption evidence. Popularity is supporting evidence, however, and does not outweigh the active maintenance signals.
Three workflows lack top-level token permissions and three declare write access, while none declare read-only permissions. This is a workflow-hardening gap, though it does not by itself indicate package abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spatie/invade Version ^2.1 | — | — |
filament/tables Version ^5.0 | — | — |
filament/support Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.