Documentation and packaging are complete, with a clear license and release notes. Recent work is concentrated in one contributor, and the workflow audit found a high-confidence bot-condition issue; organization backing and Dependabot provide some mitigation.
70%
Total Score
67
100
100
100
One contributor made all two commits in the last three months. The organization-owned project can potentially hand off maintenance, but observed activity still has a narrow contributor base.
Only two commits were made in the last three months. Recent release activity offsets this somewhat, but the source activity is limited.
All five workflows were analyzed and all 12 action references are pinned, with no untrusted checkout or script-injection findings. However, a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow, and three workflows grant top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.