Clear documentation, tests, licensing, and a matching repository make integration easier. The workflow has no audit findings, but its actions are unpinned and the project has no security policy.
66%
Total Score
75
100
89
67
The repository is owned by an individual user rather than an organization, so there is no demonstrated organizational handoff capacity to offset the concentrated contributor base.
The package is only 53 days old, with four releases clustered within minutes and no longer-term maintenance history. This limits evidence of durability despite the recent release activity.
One contributor made all eight commits in the last three months. With a user-owned project and no second active contributor, maintenance is concentrated in a single person.
The repository uses Composer build tooling, but no security-scanning tool was detected. That is a transparency and maintenance-process gap, not evidence of a defect.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
morilog/jalali Version ^3.5 | — | — |
filament/filament Version ^5.0 | — | — |
illuminate/support Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.