The package is well documented and includes release notes, tests in the repository, and a security policy. Its small contributor base and two workflows with broad write permissions merit monitoring, but recent releases and active pull-request merging show ongoing maintenance.
88%
Total Score
75
100
83
The package runs a post-autoload-dump install lifecycle script. This adds some install-time behavior, but the signal provides no evidence that the script is unsafe or unusually broad.
The registry namespace and repository are owned by the same individual account, so there is no organization-level backing to offset the concentrated contributor activity. Recent releases and a second active contributor provide partial practical support.
Two contributors were active in the last three months, with the top contributor responsible for 75% of commits. The second active contributor provides some coverage, but ownership remains concentrated.
All three workflows were analyzed, all eight action references are pinned, and no audit findings or untrusted-checkout sinks were detected. Two workflows grant top-level write permissions, which is a mild hygiene concern but not a severe risk without an untrusted trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jenssegers/agent Version ^2.6 | — | — |
filament/filament Version ^5.3 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.