Documentation and licensing are in place, and the source tree is small and focused. The workflow audit found a high-confidence template-injection pattern, so inspect that automation before production use.
76%
Total Score
100
86
100
All three releases were published within about 3 minutes, and the package is only 85 days old. This shows an initial burst but provides limited evidence of a sustained release cadence.
Version 3.0.0 is not marked prerelease, but the signal reports 1.0.0 as the latest version, which conflicts with the assessed release and reduces confidence in the registry metadata.
All three workflows were analyzed with no untrusted checkouts, script injection, or unpinned action references. However, the audit found one high-confidence template-injection pattern in update-changelog.yml, which is a workflow hygiene concern even without a dangerous trigger or sink reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/spatie-laravel-settings-plugin Version ^5.0 | — | — |
jeffersongoncalves/filament-plugin-core Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.