Documentation and licensing are clear, and the repository includes security reporting. Its short history limits confidence about long-term support.
82%
Total Score
100
93
75
The package runs a post-autoload-dump install-time script. This is a mild supply-chain and installation-review concern because code executes during Composer installation.
This is a very new package: it is 26 days old and has only one release. That limits evidence of long-term maintenance, despite recent repository activity.
All 5 workflows were analyzed successfully, all 16 action references are pinned, and no audit findings or untrusted checkouts were reported. Two workflows grant top-level write permissions, which is a mild hygiene concern without an accompanying untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^4.0 | — | — |
filament/filament Version ^5.0 | — | — |
saloonphp/laravel-plugin Version ^4.3 | — | — |
saloonphp/pagination-plugin Version ^2.3 | — | — |
saloonphp/rate-limit-plugin Version ^2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.