Healthy and reasonable to depend on; it has a long release history, frequent recent releases, tests, and a matching organization-backed repository. Recent development is concentrated in one contributor, and the repository lacks a security policy and explicit workflow permissions.
84%
Total Score
67
100
94
80
All recent commit activity comes from one contributor, creating concentration risk; the organization backing provides some ability to hand maintenance off, but no second active contributor is shown.
Only one commit was recorded in the last three months, so current hands-on development is limited despite the recent release history.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency gap, though it is partly offset by the repository's tests and CI workflow.
No repository security policy was found, leaving vulnerability-reporting expectations undocumented.
The repository's only workflow has no top-level token permissions declaration. No write permissions were detected, but the absence of an explicit restrictive policy is a workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.