Documentation and licensing are solid, and the source tree includes tests. Automation also has a broad write token, a spoofable bot condition, and an unpinned container image. The package is not deprecated or archived, but its maintenance evidence is weak.
43%
Total Score
0
75
50
The package has had 7 releases but none in the last 12 months, and its latest release was over three years ago. This is strong evidence of abandonment risk for a package users may need to keep compatible with current Laravel and Filament versions.
The repository recorded 0 commits and 0 active maintainers in the last three months, while its last push was over three years ago. No provided activity signal compensates for this maintenance gap.
All 8 analyzed action references are unpinned, and high-confidence findings flag a spoofable bot condition and an unpinned container image. A workflow also grants top-level write permissions; these are meaningful supply-chain hygiene weaknesses, although no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^2.0 | — | — |
illuminate/contracts Version ^8.0|^9.0 | — | — |
spatie/laravel-package-tools Version ^1.9.2 | — | — |
filament/spatie-laravel-tags-plugin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.