A clear README, release notes, tests, and matching source repository make the package easier to adopt. Its broad dependency surface and absent security policy leave additional maintenance exposure.
58%
Total Score
83
50
93
50
All 12 action references are unpinned, and high-confidence findings identify spoofable bot conditions and a floating latest container image. The audit covered all four workflows with no untrusted checkout or script-injection findings, limiting but not removing the risk.
The release declares 27 runtime dependencies, including many integrated plugins, increasing upgrade and compatibility exposure for consumers. This is consistent with the package's role as a central integration package but still raises maintenance complexity.
The package is 498 days old with 14 releases, but it has had no registry release in the last 12 months; the short 4.1-day median interval shows earlier activity rather than current maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful sign of slowed maintenance despite a recent repository push being visible elsewhere.
The linked repository has no security policy, reducing transparency for vulnerability reporting. Dependabot and security-checker tooling provide some compensating security process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mews/purifier Version ^3.4 | — | — |
hasnayeen/themes Version ^3.0 | — | — |
filament/filament Version ^3.0 | — | — |
illuminate/contracts Version ^10.0||^11.0||^12.0 | — | — |
tapp/filament-maillog Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.