A documented security policy, MIT license, and pinned actions improve transparency. Organization backing and a matching repository help offset the single recent contributor and workflow audit gap.
72%
Total Score
75
100
100
88
One contributor made all commits in the last 3 months, concentrating recent maintenance in a single person. Organization ownership partly reduces handoff risk but does not remove the observed concentration.
Only 1 commit was recorded in the last 3 months, showing limited recent development activity; the recent release history and latest push provide some compensation.
All 5 workflows were analyzed and all 10 action references are pinned, with no untrusted checkout or script-injection findings. However, one high-confidence bot-conditions finding affects the pull_request_target Dependabot auto-merge workflow, and 1 file failed auditing.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.