The package is clearly identified and documented, with MIT licensing, a matching source repository, and tests maintained there. Organization backing and Dependabot scanning provide useful support despite the maintenance and workflow concerns.
58%
Total Score
75
93
50
The package has 10 releases since July 2023, but its latest registry release was nearly two years ago and it had no releases in the last 12 months, indicating materially slowed maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which leaves current maintenance capacity uncertain despite the repository not being archived.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. Dependabot scanning partly offsets this maintenance-transparency gap.
All 12 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; its pull-request trigger and write permissions make this a meaningful workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0-stable | — | — |
spatie/laravel-data Version ^4.5 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
ibecsystems/admin-kit-core Version ^3.6 | — | — |
spatie/laravel-translatable Version ^6.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.