The package includes a clear license, README, changelog, repository tests, and release notes. Its workflow audit found only low-severity hygiene issues; consider pinning a later release after maintenance history is established.
68%
Total Score
50
94
67
The package runs a post-autoload-dump install-time script. This adds execution complexity during installation, though no accompanying evidence shows that it is harmful.
Only one registry publishing account is listed, and the repository owner is an individual rather than an organization, leaving a thin visible maintainer base.
The package is only 1 day old with two releases, so its maintenance record and long-term stability are not yet established.
No commits or active maintainers were recorded in the last 3 months. Because the project is only 1 day old, this is an early maintenance gap rather than evidence of established abandonment.
All five workflows were analyzed with no untrusted checkout or script-injection findings and all 19 action references pinned. Two workflows use broad top-level write permissions and three high-confidence low-severity adhoc-package findings remain, so this is a minor hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 || ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.