The source tree has tests, a changelog, a matching repository, and MIT licensing. The workflows use nine unpinned actions and include a high-confidence bot-condition finding; recent development also shows no commits.
58%
Total Score
50
100
90
67
The registry namespace and repository are owned by the same individual account, providing clear ownership but no organizational backing or broader maintenance capacity.
This is a young package, about 5 months old, with only one release and no established release cadence. That limits evidence of long-term maintenance but is not abandonment by itself.
The repository recorded no commits and no active maintainers in the last 3 months. With only one release, this provides limited evidence of ongoing maintenance and raises abandonment risk.
No repository security policy was found. This is a minor transparency gap for reporting vulnerabilities, though it does not outweigh the available maintenance evidence on its own.
All four workflows were analyzed, but all nine action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a meaningful hygiene concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.