The package includes a clear README, release notes, tests in the repository, matching licensing, and security tooling. Its very recent history leaves long-term maintenance unproven, and the workflow audit found a high-confidence bot-condition issue.
68%
Total Score
88
100
94
88
Seven releases were published within the first day of the observed package history, showing active initial delivery but providing no evidence of maintenance over a longer period.
No commits or active maintainers were measured during the last three months. Because the package is only one day old and was recently pushed, this is an important coverage limitation and a maintenance concern rather than proof of abandonment.
All nine workflows were analyzed, all action references are pinned, and jobs use read-only permissions. However, the high-confidence bot-conditions finding in dependabot-auto-merge.yml indicates a workflow authorization weakness that warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.13.3 || ^5.8.3 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
happenv-com/laravel-access-control Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.