It includes a clear MIT license, useful documentation, repository tests, and release notes for this version. Pin v1.2.0 if you adopt it.
67%
Total Score
50
92
50
The package runs a post-autoload-dump installation lifecycle script. This is an additional install-time execution surface, though the signal does not show malicious behavior or unusually broad scripting.
The package has seven releases over about 2 years and a latest release in December 2025, but only one release in the last 12 months indicates a slower cadence.
The repository recorded no commits and no active maintainers in the last 3 months. A recent release and push provide some compensating evidence, but current maintenance activity is limited.
No security policy is present, which leaves vulnerability reporting and handling less transparent for a package used in applications.
All 12 action references are unpinned, and three workflows grant top-level write access. The audit also found a high-confidence bot-condition issue in a Dependabot auto-merge workflow; no untrusted checkout or script injection was found, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
laravel/framework Version ^10.0|^11.0|^12.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
spatie/laravel-cookie-consent Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.