The source project includes tests, a changelog, a security policy, and pinned workflow actions. One high-confidence workflow finding warrants care around its changelog automation.
68%
Total Score
75
94
88
The package is newly published: all three releases occurred on the same day, so there is not yet enough history to demonstrate sustained maintenance.
No commits or active maintainers were observed in the last three months. Because the package was released today, this is an early maintenance gap rather than proof of abandonment.
All four workflows were analyzed and all ten action references are pinned, but the audit found a high-confidence template-injection issue in update-changelog.yml; the single top-level write permission is only a mild concern without an untrusted trigger or checkout.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
jeffersongoncalves/laravel-carve Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.