This is a healthy, actively developed v1.0.0 package with a matching repository, recent release activity, substantial recent commit activity, repository tests, CI tooling, a security policy, and no deprecation or archival indicators. The main reservations are its young age, small popularity footprint, single registry publisher, and one workflow with top-level write permissions; these are meaningful but do not outweigh the evidence of active maintenance and transparent project structure.
85%
Total Score
80
100
94
90
Only one registry account, Jim, has publish access, which is a modest publishing bus-factor concern for a user-owned project. However, repository activity shows a second active contributor, partly mitigating the concern.
The repository is owned by the user account oddvalue rather than an organization, so there is no organizational maintenance-backing signal; the active two-contributor history provides partial practical support.
The repository has only 5 stars and 1 fork, so external adoption evidence is limited; this is supporting context rather than a health failure because maintenance indicators are strong.
Three workflows use read-only permissions, but fix-code-style.yml has top-level write permissions, creating a workflow-hardening gap even though no dangerous workflow pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.13|^5.8 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.