The source is organized and backed by an organization, with repository tests, release notes, and dependency scanning. Workflow hygiene is weak, with every analyzed action reference unpinned and a high-confidence bot-condition finding.
58%
Total Score
75
94
50
The package has had only three releases, with the latest on December 17, 2024 and none in the last 12 months. That suggests slowing maintenance, although the repository was pushed more recently.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, even though the repository is not archived.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. Dependabot is enabled, which provides some compensating security maintenance.
All 12 analyzed action references are unpinned, three workflows grant top-level write access, and the audit found a high-confidence bot-condition issue. No untrusted checkout or script-injection sink was found, limiting this to workflow hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0-stable | — | — |
spatie/laravel-data Version ^4.5 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
ibecsystems/admin-kit-core Version ^3.1 | — | — |
joshembling/image-optimizer Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.