Usable with caveats: the package is licensed, documented, tested in its repository, and has recent stable releases, but repository activity has stopped and several pull requests remain open. Review the maintainer's ongoing support before adopting it for a critical dependency.
68%
Total Score
63
100
100
75
One of five workflows uses pull_request_target for Dependabot auto-merge, which increases automation exposure, although no untrusted checkout or script-injection patterns were detected.
Only one account has registry publish access, which creates a narrow publishing path; the organization-owned repository provides some backing but does not remove the single-publisher concentration.
The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign that maintenance has recently stalled despite the repository not being archived.
There are six open pull requests with no merges in the last month and no new issue activity, suggesting changes may be waiting for maintainer attention.
Three workflows request top-level write permissions and two declare no top-level permissions, leaving broader-than-necessary or unclear token access in part of the CI configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 || ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.