Package Health

noin/filament-activity-log

The MIT license, matching repository, recent publishing, and two active contributors provide a solid foundation. Documentation and release notes are present, though the project remains relatively small and its workflow maintenance is imperfect.

Latest v4.0.0-beta1.0.6PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Project backingcaution

The repository is owned by an individual account rather than an organization, so the small contributor base provides less formal handoff capacity; the two active contributors partly offset this.

Repo popularitycaution

The repository has only 2 stars, 1 fork, and no watchers. This is weak supporting evidence, but popularity alone does not outweigh the active release and contributor signals.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap rather than evidence of abandonment.

Version stabilitycaution

This release is a prerelease while the package has since reached stable major version 5.2.0, so depending on this beta carries some avoidable stability risk.

Workflow auditcaution

All three workflows were analyzed without high-confidence findings, untrusted checkouts, or script injection. However, 9 of 10 action references are unpinned and one workflow grants top-level write access, creating a meaningful maintenance and supply-chain hygiene caveat.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Noxo

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^3.0.95 || ^4.0
dragon-code/support
Version ^6.3
spatie/laravel-activitylog
Version ^4.7
malzariey/filament-daterangepicker-filter
Version ^4.0

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform