Documentation and project controls add useful confidence. The repository is young, with three releases over 47 days, and version metadata conflicts with the assessed 3.0.0 release. Tests, active commits, and a security policy offset the workflow hygiene finding.
78%
Total Score
90
100
83
100
The repository is owned by an individual account rather than an organization, so the two-contributor activity provides useful but limited maintenance backing.
The package is only 47 days old and has three releases published within roughly one day, so long-term maintenance capacity is not yet demonstrated.
The repository has only 2 stars and no forks, indicating limited external adoption; this is supporting context rather than a health verdict.
The assessed release is 3.0.0, but the collected latest_version is 1.0.0; although the release is marked stable and not prerelease, this version inconsistency reduces confidence.
All four workflows were analyzed, all 11 action references are pinned, and no untrusted checkout or script injection was found. A high-confidence template-injection finding in update-changelog.yml remains a workflow hygiene concern, but no dangerous trigger or sink corroborates it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.3 | — | — |
spatie/laravel-medialibrary Version ^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
jeffersongoncalves/laravel-cms Version ^1.0 | — | — |
jeffersongoncalves/filament-translatable Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.