The organization provides some handoff capacity, and the release includes tests, notes, and a clear README. Its short history and one-contributor record leave maintenance less proven, while all seven workflow actions are unpinned.
72%
Total Score
67
94
50
This is a young package, first released 59 days ago, with only one release and no established release cadence. That limits evidence of long-term maintenance.
All four recent commits come from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
Four commits from one active maintainer in the last three months show initial development activity, but the small amount of activity provides limited evidence of ongoing support.
No repository security policy was found. This is a transparency gap for reporting and handling security issues, though it is not evidence of maliciousness.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or auditor findings. However, all seven action references are unpinned, and one workflow grants top-level write permissions, creating avoidable supply-chain and token-scope risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.