The release includes usable documentation, a changelog, repository tests, and dependency scanning. CI has broad token permissions, all 12 actions are unpinned, and its Dependabot auto-merge check has a high-confidence bot-condition finding.
58%
Total Score
75
93
50
The package runs a post-autoload-dump install-time script. This deserves awareness during installation, but the signal alone does not show an unsafe or unusual action.
The package has had 4 releases since February 2024, but none in the last 12 months; the latest release was over two years ago, which raises maintenance risk for a framework integration.
The repository recorded 0 commits and 0 active maintainers in the latest three months, weakening evidence of ongoing maintenance despite the repository being active more recently.
No SECURITY.md policy is present, leaving vulnerability reporting and response expectations undocumented.
The audit analyzed all 5 workflows and found no untrusted checkout or script injection, but all 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects Dependabot auto-merge.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0-stable | — | — |
spatie/laravel-data Version ^4.5 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
ibecsystems/admin-kit-core Version ^3.1 | — | — |
joshembling/image-optimizer Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.