The package is clearly documented and its repository remains active under organization backing. The single unpinned workflow action, absent security policy, and inconsistent reported version data leave modest transparency and build-reproducibility concerns.
78%
Total Score
100
50
89
83
Nine runtime dependencies, including Laravel Nova and several related Marshmallow packages, create a relatively broad dependency surface for a framework integration and increase upgrade coupling.
Five stars and one fork indicate limited adoption, but popularity is supporting evidence only and does not outweigh the package's active maintenance signals.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures unclear for a package integrated into application code.
The release is marked as a stable major and not a prerelease, but the reported latest version is v3.5.3 while the assessed release is v5.2.1, an inconsistency that weakens metadata confidence.
The sole workflow was fully analyzed with no audit findings or untrusted execution sinks. However, its one action is unpinned, which leaves a minor build-reproducibility and action-change risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/nova Version ^5.0 | — | — |
marshmallow/commands Version ^1.0 | — | — |
marshmallow/mr-mallow Version ^1.0 | — | — |
marshmallow/translatable Version ^5.0 | — | — |
marshmallow/nova-flexible Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.