The repository includes tests, release notes, a security policy, and active recent work. Its beta status, one-release history, single active contributor, and workflow audit finding make long-term continuity less certain.
67%
Total Score
83
81
83
This package is brand new: it has one release and is 0 days old, so there is no release track record to establish maturity or sustained maintenance.
All 5 recent commits came from one contributor, leaving maintenance highly concentrated. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has 5 stars and no forks or watchers, indicating limited adoption evidence. This is supporting context rather than a health verdict, especially for a newly released package.
The assessed version is v1.0.0-beta.1 and all recent releases are prereleases; the included notes explicitly warn that names and configuration may change before 1.0.
All four workflows were analyzed and all action references are pinned, with no untrusted checkout or script injection found. However, the audit identified a high-confidence bot-conditions finding in the Dependabot auto-merge workflow, and two workflows grant top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
packstub/session-replay Version ^1.0 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.