The package includes tests, a substantial README, and a source repository that clearly matches it. Its workflow actions are all unpinned, the license files include Apache-2.0 alongside the MIT declaration, and no security policy is present.
62%
Total Score
50
88
50
The artifact declares MIT and includes license files, so licensing is present; however, detected license text also includes Apache-2.0, which the declaration does not cover. The mismatch warrants clarification before adoption.
Only one registry publishing account is listed, and the project is backed by a personal repository rather than an organization. This leaves a thin visible publishing base and increases continuity risk.
The repository recorded 0 commits and 0 active maintainers in the past three months, despite the release being only about five months old. This is meaningful evidence of slowed maintenance, though the project is still unarchived and has a recent release.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, although the repository is active enough to remain unarchived.
The audit covered all 1 workflow and found no dangerous triggers or high-confidence findings, but all 6 action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.