The project has clear documentation, release notes, repository tests, and a second active contributor. Its main weakness is a high-confidence workflow template-injection finding, while security-policy coverage is also limited.
79%
Total Score
100
93
75
Six releases in the first 86 days show active early development, although the short history and same-day release clustering provide limited evidence of long-term stability.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a modest transparency gap for a maintained package.
All four workflows were analyzed and all 13 action references are pinned, with no untrusted checkout or script-injection trigger. However, the high-confidence template-injection finding in update-changelog.yml is a real workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
jeffersongoncalves/laravel-pwa-favicon Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.