Usable with caveats: the package is actively released, documented, licensed, and backed by a matching organization repository with tests and security tooling. Maintenance is concentrated in one contributor, and several workflows use broad write permissions, so review updates before depending on it heavily.
68%
Total Score
63
100
89
70
One workflow uses pull_request_target for Dependabot automation. No untrusted checkout or script-injection pattern was detected, which limits the concern, but this trigger still warrants review because it can run with elevated repository context.
The package declares a post-autoload-dump install-time script. This is a real execution surface during Composer installation, though the signal does not show a dangerous script or an unusual number of lifecycle hooks.
All four recent commits came from one contributor, creating a meaningful single-person maintenance dependency. Organization ownership provides some ability to hand work off, but no second active contributor is shown.
There were four commits in the last three months, so activity has not stopped, but the pace is modest for a project whose releases are frequent.
There are no open issues and four open pull requests, with one new pull request in the last month. The lack of merged pull requests recently leaves some uncertainty about review and maintenance throughput.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/tables Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.