Usable with caveats: the package is licensed, clearly backed by an organization, tested in its repository, and has release notes for this version. However, it has made no release in 12 months and no commits in about 5 months, so ongoing maintenance is uncertain.
60%
Total Score
75
50
89
63
One workflow uses pull_request_target, but the analyzed workflows contain no untrusted checkouts or script injection patterns. The configuration warrants review but is not severe on the available evidence.
Six runtime dependencies, including Filament and related Laravel packages, create a moderate compatibility surface but are consistent with the package's framework integration role.
The package runs a post-autoload-dump lifecycle script during Composer installation. This is an install-time execution surface, though the signal provides no evidence that the script is unsafe.
Although the package had 20 releases with a fast early cadence, it has had no releases in the last 12 months. That is a meaningful maintenance concern for a package whose latest release is now old.
The repository recorded no commits and no active maintainers during the last 3 months, despite a more recent push date, so current development activity appears limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
nette/php-generator Version ^4.1 | — | — |
bezhansalleh/filament-shield Version ^3.3 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
solution-forest/filament-tree Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.