The repository includes tests and a substantial README, and it is not archived. One maintainer, no security policy, and no observed commit activity leave limited evidence of long-term support.
63%
Total Score
67
100
88
50
The package runs a post-autoload-dump lifecycle script during installation, adding execution behavior that deserves more trust than a package with no install-time scripts.
Only one registry account has publish access, which creates a thin publishing base. The linked repository is also owned by an individual rather than an organization, so no broader backing compensates for that limitation.
This is the package's first release, published 0 days ago, so there is no release track record or demonstrated maintenance cadence yet.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Because the package is only 0 days old, this is not proof of abandonment, but it leaves maintenance capacity unproven.
The repository uses Composer build tooling, but no security scanning tools were detected. That is a modest transparency and hygiene gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^4.0||^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.