It includes a README, tests, an MIT license, and a security policy, and the repository clearly matches the package. The workflow uses unpinned actions and broad write permissions, adding a smaller maintenance risk.
58%
Total Score
0
67
75
This is the package's only release, published in November 2023, with no releases in the following 12 months; that is a meaningful maintenance concern for a v0.1.0 plugin.
There were no commits or active maintainers in the measured three-month period, reinforcing the concern raised by the single-release history and indicating weak current maintenance.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and assurance gap rather than evidence of abandonment.
The assessed release is v0.1.0 rather than a stable major release, so compatibility and maturity remain less established despite the absence of a prerelease label.
The only workflow was fully analyzed and has no untrusted checkout, injection, or auditor findings, but all three actions are unpinned and the workflow grants top-level write permissions, creating a mild supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.