A single maintainer and only two recent commits leave limited continuity if the owner steps away. The workflows are fully audited, but one high-confidence bot-condition finding warrants a small operational caveat.
76%
Total Score
50
100
100
75
The package runs a post-autoload-dump install-time script. This adds some installation complexity, but the signal provides no evidence that the script is unusually risky.
The package and repository are owned by the same individual account rather than an organization, so the concentrated maintainer activity represents genuine continuity risk.
One contributor made 100% of the two recent commits, leaving the project dependent on one person's continued availability.
Only two commits were recorded in the last three months, so maintenance activity is present but fairly light for a package with a single active contributor.
All five workflows were analyzed successfully, all 12 action references are pinned, and no untrusted checkout or script-injection sinks were found. A high-confidence bot-conditions finding and broad top-level write permissions warrant a minor workflow-hygiene caveat, without evidence of a severe release-path risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^4.0|^5.0 | — | — |
filament/filament Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.