The MIT license, substantial README, and repository tests and changelog make the package easier to evaluate. CI uses unpinned actions and has a high-confidence bot-condition finding, adding release-process risk.
40%
Total Score
0
88
Only three releases were published, all in a short period ending on March 10, 2024; there have been no releases for about 2 years and 6 months, which is a strong abandonment concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, providing no evidence of ongoing maintenance.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this remains a caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
livewire/livewire Version ^3.0 | — | — |
illuminate/contracts Version ^9.0|^10.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.