Repository tests, a changelog, a security policy, and matching package references provide useful project structure. MIT licensing and release notes improve transparency, but the workflow audit reports a high-confidence bot-condition issue and all seven action references are unpinned.
52%
Total Score
75
94
67
The package uses a post-autoload-dump install-time script, which adds execution during installation. This is common in Composer packages but remains a small supply-chain and installation-complexity concern.
The package has only four releases and none in the last 12 months, despite being about 15 months old. This suggests maintenance has stalled and is not offset by the available repository structure.
The repository recorded zero commits and zero active maintainers in the last three months. That is a concrete maintenance concern for a package with ongoing framework dependencies.
The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, and all seven analyzed action references are unpinned. There were no untrusted checkouts or script injections, but the workflow hygiene still lowers confidence in the release process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
awcodes/filament-curator Version ^3.7 | — | — |
cviebrock/eloquent-sluggable Version ^10.0 || ^11.0 || ^12.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
solution-forest/filament-tree Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.