The project shows strong release coverage, clear upgrade notes, licensing, tests, and security documentation. Its recent commit count is zero, while workflow checks report high-confidence issues and every action reference is unpinned.
58%
Total Score
75
100
67
The package runs a post-autoload-dump install-time script, which adds execution surface during Composer installation and warrants caution even though no harmful behavior is shown here.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign that maintenance may have recently stalled despite the broader release history.
All 11 action references are unpinned, four workflows grant top-level write permissions, and high-confidence bot-condition and template-injection findings were reported. The pull_request_target workflow has no untrusted checkout, so these are workflow hygiene concerns rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kalnoy/nestedset Version ^6.0|^7.0 | — | — |
filament/filament Version ^5.0 | — | — |
laravel/framework Version ^11.0|^12.0|^13.0 | — | — |
php-ffmpeg/php-ffmpeg Version ^1.2 | — | — |
spatie/eloquent-sortable Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.