The package has an MIT license, tests, a changelog, and a clear source tree. Its workflow audit is incomplete, and both analyzed actions are unpinned, leaving maintenance and build-reproducibility concerns.
62%
Total Score
75
100
86
83
Only two releases exist, with none in the last 12 months; the latest release was about 9 months ago, which suggests limited ongoing maintenance for a dependency.
There were zero commits and zero active maintainers in the last 3 months, indicating that active development has currently stopped or slowed substantially.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest source-project hygiene gap.
The repository has no security policy, so it provides no documented path for reporting vulnerabilities or explaining security maintenance.
The audit analyzed only 1 of 2 workflows because 1 file failed, and both analyzed action references were unpinned. No dangerous triggers, untrusted checkouts, or audit findings were reported, which partly offsets the reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^3.0 | — | — |
illuminate/contracts Version ^10.0|^11.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.