Package Health

jeffersongoncalves/filament-additional-information

The package includes a clear README, license, and repository tests, while recent work involves two active contributors. Its focused dependency set and security tooling add useful maintenance context.

Latest 3.0.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

The package uses a post-autoload-dump install-time script. This adds execution surface during installation, but the signal provides no evidence that the script is unsafe.

Project backingcaution

The repository is owned by the same individual namespace as the package, so ownership is clear, though the project does not have organizational backing.

Release historycaution

Only three releases exist, all published within minutes and within the first 85 days of the package's life. This is limited evidence of sustained release practice, despite all three releases occurring in the last year.

Version stabilitycaution

The assessed version is a stable major release, but the collected latest version is 1.0.0 rather than 3.0.0. That mismatch reduces confidence in the version metadata and warrants caution.

Workflow auditcaution

All four workflows were analyzed successfully, with no untrusted checkouts, script injection, or unpinned action references. A high-confidence template-injection finding in update-changelog.yml is a workflow hygiene concern, but it is not independently a severe dependency-health risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jefferson Gonçalves

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^5.0
—
—
spatie/laravel-package-tools
Version ^1.14.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform