Documentation, tests, release notes, and an MIT license make adoption straightforward. The repository is organization-backed and not archived, though its workflow permissions and action pinning need attention.
61%
Total Score
83
100
100
50
The package runs a post-autoload-dump install-time script. This is a supply-chain and installation-behavior consideration, though the signal does not show a dangerous script action.
The repository recorded zero commits and zero active maintainers in the last three months. That recent pause lowers confidence in ongoing maintenance, even though the project has a recent release and a longer release history.
No SECURITY.md or equivalent security policy was found. This is a transparency gap for a maintained package, though it does not by itself indicate unsafe code.
All eight analyzed action references are unpinned, all three workflows grant top-level write permissions, and a high-confidence template-injection finding was reported. No untrusted checkout or script-injection trigger was found, so these are workflow-hygiene concerns rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/schemas Version ^4.0|^5.0 | — | — |
filament/support Version ^4.0|^5.0 | — | — |
filament/widgets Version ^4.0|^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.