Documentation, repository tests, release notes, and a security policy make the project easy to assess. Maintenance capacity is thin because only one contributor made one commit in the last three months.
68%
Total Score
67
100
100
One contributor made all recent commits, leaving the observed maintenance activity concentrated in a single person; organization backing partly offsets the handoff risk.
Only one commit was recorded in the last three months, indicating that active maintenance has recently slowed.
All five workflows were analyzed and all 12 action references are pinned, with no untrusted checkout or script-injection findings. However, a high-confidence bot-conditions finding affects the pull_request_target Dependabot auto-merge workflow, and one workflow grants top-level write access.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-translatable Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.