It has a clear MIT license, useful README, repository tests, and Dependabot scanning. Workflow checks still need tightening because every action reference is unpinned and one high-confidence bot-condition issue affects an auto-merge workflow.
45%
Total Score
0
83
50
The package has only one release, published about 1 year and 17 days ago, with no releases in the last 12 months. That leaves little evidence of an established maintenance track.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the concern that maintenance may have stopped after the initial release.
No security policy was found in the repository. This is a transparency gap for a package with little other evidence of ongoing maintenance.
All 12 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue in the auto-merge workflow. The pull_request_target workflow has broad write permissions, but no untrusted checkout or script-injection sink was observed, limiting this to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^v4.0.3 | — | — |
filament/widgets Version ^v4.0.3 | — | — |
livewire/livewire Version ^3.0 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.