Usable with caveats: the package is licensed, documented, actively released, and backed by a matching organization repository. However, it has had no commits from active maintainers in the last three months, while several workflows use write permissions and one handles pull-request automation.
68%
Total Score
83
100
94
75
Five workflows were analyzed with no untrusted checkouts or script injection, but one pull_request_target workflow performs Dependabot auto-merge, which warrants caution because that event type can expose elevated workflow privileges.
The repository recorded zero commits and zero active maintainers in the last three months, a real maintenance concern despite the recent release history and repository push.
Four workflows declare top-level write permissions and one test workflow declares none, leaving a broader-than-necessary automation permission surface even though no direct exploit was observed.
The assessed release is marked as a stable major and is not a prerelease, with only 5% recent prereleases. The reported latest version being 2.0.3 while assessing 3.0.2 is inconsistent and reduces confidence in the version metadata.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/eloquent-sortable Version ^4.0.0|^5.0.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.