It has a clear MIT license, useful documentation, repository tests, and a release in January. Workflow checks found an unsafe bot condition and all 13 actions are unpinned, while recent development activity is limited.
58%
Total Score
50
100
100
75
Only one registry account has publish access. That is a thin publishing base for a user-owned project and leaves limited visible redundancy if the maintainer becomes unavailable.
The repository is owned by a user account rather than an organization, so there is no observed organizational backing to offset the single-maintainer and inactive-commit concerns.
There were zero commits and zero active maintainers in the past three months. This is a meaningful maintenance concern, though the January 2026 release shows the project was recently updated.
There is only one open issue and one open pull request, with no new or closed activity in the past month. The small queue is not severe, but the lack of recent movement reinforces the maintenance concern.
All six workflows were analyzed, but all 13 action references are unpinned and a high-confidence bot-conditions finding reports that actor context may be spoofable. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is workflow hygiene risk rather than a severe standalone dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
glorand/laravel-model-settings Version ^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.