Usable with caveats: the package is licensed, clearly matched to its repository, and has tests and a changelog in source, but maintenance has gone quiet since the latest release and the repository lacks several security-hygiene safeguards.
63%
Total Score
50
100
94
63
A post-autoload-dump script is present, which is an install-time execution point and deserves review, but the signal does not show a dangerous script or otherwise establish severe risk.
The registry namespace and repository owner match, with a user-owned project rather than organizational backing. This is consistent and transparent, though it provides a thinner continuity cushion than an organization-backed project.
The repository has had no commits and no active maintainers in the last three months; combined with the latest release being about five months ago, this is a meaningful maintenance concern.
The repository uses Composer build tooling, but no security scanning tools were detected. For a package containing substantial JavaScript and upload-related functionality, that is a security-hygiene gap.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.