The package is documented, licensed, recently released, and backed by repository tests and release notes. Its maintenance depends on one contributor, while the workflow audit found a high-confidence bot-condition issue, broad write permissions, and unpinned actions.
62%
Total Score
50
100
94
75
A post-autoload-dump install script is present. This is a mild supply-chain and installation-complexity concern, but the signal does not show destructive or unexpected behavior.
The repository is owned by an individual user rather than an organization, so the single-maintainer and single-contributor findings are not offset by visible organizational backing.
One contributor made 100% of the recent commits, leaving no demonstrated backup contributor and increasing abandonment risk if that maintainer becomes unavailable.
Only 2 commits were made in the last 3 months, all by one active maintainer. Recent work exists, but the low volume and concentration reduce maintenance resilience.
The release is stable and not a prerelease, but the reported latest version (1.1.3) is lower than the assessed version 2.2.2, indicating inconsistent registry metadata that merits caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.