Package Health

happytodev/filament-comments

The package has a clear MIT license, documentation, repository tests, and dependency scanning. Its very small adoption and workflow weaknesses provide limited reassurance for a long-lived dependency.

Latest v0.1.3PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The last release was nearly four years ago, with no releases in the last 12 months. This is strong evidence of abandonment despite four releases shortly after the package launched.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, confirming that development has stopped rather than merely slowing.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and 1 watcher. Low popularity is not decisive, but it provides little outside evidence of sustained use or review.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The README mentions a policy but the collected repository evidence shows none exists.

Workflow auditcaution

All 12 action references are unpinned, and a high-confidence audit finding reports spoofable actor checks in a Dependabot auto-merge workflow. The pull_request_target trigger is ordinary by itself, but these weaknesses reduce release-process confidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Frédéric Blanc

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^2.15
—
—
illuminate/contracts
Version ^9.0
—
—
beyondcode/laravel-comments
Version ^1.3.0
—
—
spatie/laravel-package-tools
Version ^1.9.2
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform