Package Health

joaopaulolndev/filament-edit-profile

The package is well documented and includes release notes, tests in the repository, and a security policy. Its small contributor base and two workflows with broad write permissions merit monitoring, but recent releases and active pull-request merging show ongoing maintenance.

Latest v3.0.4PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install lifecycle script. This adds some install-time behavior, but the signal provides no evidence that the script is unsafe or unusually broad.

Project backingcaution

The registry namespace and repository are owned by the same individual account, so there is no organization-level backing to offset the concentrated contributor activity. Recent releases and a second active contributor provide partial practical support.

Repo bus factorcaution

Two contributors were active in the last three months, with the top contributor responsible for 75% of commits. The second active contributor provides some coverage, but ownership remains concentrated.

Workflow auditcaution

All three workflows were analyzed, all eight action references are pinned, and no audit findings or untrusted-checkout sinks were detected. Two workflows grant top-level write permissions, which is a mild hygiene concern but not a severe risk without an untrusted trigger.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

João Paulo Leite Nascimento

Direct Dependencies

DependencyLast ReleaseScore
jenssegers/agent
Version ^2.6
—
—
filament/filament
Version ^5.3
—
—
spatie/laravel-package-tools
Version ^1.15.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform