Clear licensing, documentation, repository tests, and Dependabot make the project easier to maintain. Adoption should still be conservative because updates have stopped and the automation setup has a serious weakness.
62%
Total Score
50
90
50
The audit analyzed all four workflows and found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. All nine action references are unpinned, and three workflows grant top-level write access, adding further workflow hygiene risk even though no untrusted checkout or script injection was found.
The package has six releases since July 2024, but none in the last 12 months; the latest release was about 21 months ago. That is a meaningful maintenance concern for a framework plugin.
The repository recorded zero commits and zero active maintainers in the last three months. Together with the stale release history, this suggests limited current maintenance capacity.
No security policy is present in the repository. For a library integrated into application code, that reduces transparency around reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.2 | — | — |
illuminate/support Version ^11.0 | — | — |
illuminate/database Version ^11.0 | — | — |
illuminate/contracts Version ^10.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.