The package has a matching repository with tests, release notes, a clear README, and sensible build and dependency tooling. Its workflow audit found a high-confidence bot-condition issue alongside broad write permissions, so automation should be checked before relying on releases.
62%
Total Score
50
100
94
67
The repository is owned by an individual rather than an organization, so there is no visible organizational maintenance buffer. The matching repository and included tests provide some support.
The package is only 1 day old, with 9 releases concentrated in that period. This shows active initial work but provides no evidence of sustained maintenance yet.
The repository has no commits and no active maintainers recorded in the last 3 months. Because the project is only 1 day old, this is not evidence of abandonment, but it leaves long-term maintenance unproven.
No security policy is present. This is a transparency gap for a package that integrates into application panels, though the small project's tests and dependency scanning provide some compensation.
All 5 workflows were analyzed and all 11 action references are pinned, but the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. Three workflows also grant top-level write permissions, making the automation hygiene worth addressing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
daikazu/bladewind Version ~0.1.0 | — | — |
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.