Clear documentation, repository tests, licensing, and a stable release line support adoption. The recent lack of development activity makes long-term support less certain, while the workflow setup needs tighter hygiene.
64%
Total Score
50
94
75
The package is maintained under a personal repository rather than organization backing, so visible continuity depends on an individual owner; this matters more alongside the recent absence of commits.
The package has 19 releases over roughly 2.5 years, but only 2 releases in the last 12 months, indicating a slower recent cadence than its earlier median interval of about 20 days.
The repository recorded zero commits and zero active maintainers in the last 3 months, a meaningful sign of currently paused development despite the recent release history.
All five workflows were analyzed, with no untrusted checkout or script-injection findings, but all 12 action references are unpinned and a high-confidence bot-condition finding appears in the Dependabot auto-merge workflow; this is workflow hygiene risk rather than a standalone severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
overtrue/laravel-versionable Version ^5.5.0|^6.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.