The repository is well-scaffolded, licensed, and clearly matches the package, but maintenance has not continued beyond the initial release. Workflow auditing is incomplete, and both analyzed actions are unpinned; no security policy is present.
58%
Total Score
50
100
93
67
This is the only release, published about 18 months ago, with no releases in the last 12 months. The repository is not archived, but the lack of follow-up releases raises maintenance concern.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with a project that has not received recent maintenance. The initial release included tests and release notes, which partly offsets the concern.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, not evidence that the package is unsafe.
The audit analyzed only 1 of 2 workflows and one file failed, so coverage is incomplete. Both analyzed action references are unpinned, creating a supply-chain hygiene gap, although no audited dangerous sinks or high-severity findings were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^3.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.