This is a generally healthy, actively maintained release with a clear MIT license, a matching repository, substantial documentation, repository tests and changelog coverage, ongoing releases, and no registry deprecation or archival status. The main concerns are that recent repository activity is very concentrated in one contributor, with only one commit in the last three months, and that several workflows use broad write permissions; these increase maintenance and CI supply-chain exposure but do not outweigh the package’s consistent release history and repository hygiene. It is a reasonable dependency, with normal diligence around future maintenance and updates advised.
82%
Total Score
60
100
100
70
One of five workflows uses pull_request_target, which carries elevated CI trust risk, but no untrusted checkout or script-injection patterns were detected.
The package uses a post-autoload-dump install lifecycle script. This adds some installation complexity and execution surface, though the signal does not indicate an unusually dangerous script.
Only one registry account, Saade, has publishing access. This is a modest publishing-resilience concern, although repository activity and ownership are consistent with that maintainer.
The linked repository is owned by the individual user Saade rather than an organization, so the concentrated maintainer and commit activity is not compensated by evident organizational handoff capacity.
All recent commits came from one contributor with a 100% share, creating a genuine single-maintainer continuity risk; the repository is user-owned rather than organization-owned, so there is no organizational backing to offset it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
staudenmeir/laravel-adjacency-list Version ^1.18 | — | — |
ryangjchandler/blade-capture-directive Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.