The package includes a clear README, release notes for this version, repository tests, and Dependabot scanning. Its maintenance appears to have stopped soon after publication, while the workflow audit also found a high-confidence bot-condition issue and all 12 action references are unpinned.
43%
Total Score
50
79
Only two releases were published, both within about two days in July 2023, with no releases in the last 12 months despite the package being about three years old. This is strong evidence of limited ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, and all 12 analyzed action references are unpinned; three workflows also grant top-level write permissions. The pull_request_target trigger has no untrusted checkout or script-injection sink, so the workflow risk is serious but not catastrophic.
The release is v0.2.0 rather than a stable major release, which indicates a less mature API; it is not marked as a prerelease, and the release has documented notes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^2.0 | — | — |
illuminate/contracts Version ^10.0 | — | — |
spatie/laravel-package-tools Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.