Clear licensing, documentation, and repository safeguards support integration. The package is new, so its long-term maintenance record is still limited.
82%
Total Score
100
100
94
75
A post-autoload-dump script adds install-time behavior, creating a small operational consideration, but this is common Composer package practice and no other signal indicates excessive installation complexity.
Five releases were published on the same day, showing active initial development but providing no meaningful long-term maintenance history yet.
All nine workflows were analyzed, all action references are pinned, and all workflows use read-only permissions. The auditor nevertheless found one high-confidence bot-conditions issue in the Dependabot auto-merge workflow, a contained workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.11 || ^5.6 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.