Documentation, licensing, and repository structure are in good shape. The project has had no registry release in over a year, while a high-confidence workflow check and broad write permissions add maintenance hygiene concerns.
68%
Total Score
63
100
92
83
The registry has one publishing maintainer, which is a limited publishing base. Repository activity from two contributors provides some compensating maintenance capacity.
The repository is owned by the same individual namespace as the package, so there is no organization backing to offset the small maintainer base.
There have been no registry releases in the last 12 months, which raises version freshness and abandonment concerns. Recent repository commits and a push within the last month partly compensate, but do not replace a current release.
Two contributors are active, with the leading contributor responsible for two-thirds of recent commits. This is concentrated but not a single-person project.
All workflows were analyzed and all action references are pinned, but three workflows grant top-level write permissions and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^v4.0.0-beta | — | — |
codeat3/blade-phosphor-icons Version ^2.3 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.