Documentation and release notes are unusually thorough for the published artifact. MIT licensing, read-only job permissions, and no install-time scripts reduce adoption friction.
72%
Total Score
100
79
67
The package was first released less than 2 hours ago and has only three releases, so its maintenance record is too short to establish long-term reliability. The rapid initial release activity is encouraging but does not offset the lack of history.
Composer build tooling is present, but no security-scanning tool was detected. That is a transparency and hygiene gap for a package intended to run inside application projects, though it is not evidence of a defect by itself.
The repository has no security policy, leaving no documented path for reporting vulnerabilities or describing security response expectations. This lowers transparency but does not independently make the release unfit to use.
Version 0.1.2 is not a stable-major release, which signals an evolving public API and possible breaking changes ahead. It is not marked as a prerelease, so this is a moderate maturity concern rather than a severe warning.
The single workflow was fully analyzed, uses read-only job permissions, and has no untrusted checkout or injection findings. However, all 9 action references are unpinned, so their moving targets create a reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
illuminate/contracts Version ^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.