It has a clear MIT license, a matching repository with tests, and Dependabot-backed security tooling. The workflow audit also found a high-confidence template-injection pattern, so pin this exact release and monitor the project closely.
68%
Total Score
75
100
89
75
The package is 0 days old and has six releases clustered on the first day, so there is little history to establish maintenance consistency or maturity.
The repository records zero commits and zero active maintainers over the past three months. Because the package was only released today, this is partly explained by its youth but still leaves maintenance capacity unproven.
The repository has one star and no forks, indicating limited external adoption. Popularity is supporting evidence rather than a health verdict, so this modestly limits corroboration without creating a maintenance failure by itself.
All four workflows were analyzed, all ten action references are pinned, and no untrusted checkout or script-injection path was found. One high-confidence template-injection finding and a workflow with top-level write permissions remain workflow-hygiene concerns, but neither is independently a severe adoption blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
jeffersongoncalves/laravel-sso-server Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.