It has a clear MIT license, a matching repository, repository tests, and release notes for this version. Workflow hygiene is weak, and the repository lacks a security policy, increasing maintenance and transparency concerns.
56%
Total Score
75
94
50
The package has made five releases since July 2023, but none in the last 12 months and its latest registry release was in July 2024. This indicates a meaningful maintenance slowdown despite a previously regular release interval.
The repository recorded no commits and no active maintainers in the last three months. Although the repository was pushed recently according to repository_archived, the observed commit window still shows a maintenance gap.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented. Dependabot is enabled, which provides some compensating security maintenance but does not replace a policy.
All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The audit found no untrusted checkout or script-injection sink, which limits the severity to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0-stable | — | — |
spatie/laravel-data Version ^4.5 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
ibecsystems/admin-kit-core Version ^3.1 | — | — |
spatie/laravel-translatable Version ^6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.