Healthy and suitable to use, with a small maintenance-risk caveat. The repository is active, publishes release notes, and has clear ownership and security documentation, but recent work is limited to two commits from one contributor.
82%
Total Score
80
100
100
90
The package defines a post-autoload-dump install-time script, which deserves awareness because installation can execute package logic, though this signal alone does not show harmful behavior.
All two recent commits came from one contributor, creating a concentrated maintenance risk; the organization-owned repository partly compensates by allowing responsibility to be handed off.
Only two commits were made in the last three months, so maintenance activity is light, but the repository was recently updated and the package has continued releasing versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.