Workflow references are all unpinned, and the repository has no security policy or security-scanning tools. The README, license, release notes, repository tests, and recent merged pull requests provide useful transparency and signs of active initial development.
68%
Total Score
83
79
50
A post-autoload-dump install-time script is present. This is worth noting because it adds installation behavior, but the signal does not show that the script is unsafe or unusually broad.
The package is only 0 days old with two releases, so there is little evidence of sustained maintenance or long-term stability. The rapid second release and repository activity provide some early support but do not establish a track record.
No commits or active maintainers were recorded in the last three months, despite the recent release and merged pull requests. Because the project is brand new, this is concerning evidence of limited history rather than proof of abandonment.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest repository hygiene gap for a package that handles application integrations.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.8.4 | — | — |
livewire/livewire Version ^4.4 | — | — |
illuminate/contracts Version ^13.0 | — | — |
enshrined/svg-sanitize Version ^1.0 | — | — |
blade-ui-kit/blade-icons Version ^1.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.