The repository shows 19 commits in the last three months, two active contributors, security tooling, and a security policy. The workflow audit found one high-confidence template-injection issue, but no untrusted checkout or script-injection path.
84%
Total Score
88
100
88
100
The package and repository are owned by the same individual account, so the source ownership is consistent, though it does not provide organizational backing.
Six releases were published within the package's first day, showing initial activity but providing little evidence of sustained release history over its 88-day lifetime.
The assessed version is 3.0.1 while the collected latest version is 1.0.1; this inconsistency weakens confidence in the registry metadata and release positioning.
All three workflows were analyzed, all nine action references are pinned, and no untrusted checkout or script-injection path was found. A high-confidence template-injection finding in update-changelog.yml remains a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/support Version ^5.0 | — | — |
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.