MIT licensing, detailed documentation, and repository tests support adoption. The project is very new, while its workflows use eight unpinned actions and lack a security policy; organization backing and recent development reduce the concern.
72%
Total Score
100
83
50
This is the package's only release, published on the assessment date, so there is not yet evidence of a sustained release history.
The repository has no security policy, leaving disclosure and response expectations undocumented; this is a transparency gap rather than evidence of an unsafe release.
Version 0.1.0 is an early, non-stable-major release, which indicates more API and compatibility risk than a mature stable release.
All eight analyzed action references are unpinned, and one workflow grants top-level write permissions. The audit found no untrusted checkouts, injection sinks, or other recorded workflow findings, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.8.4 | — | — |
illuminate/contracts Version ^13.0 | — | — |
syriable/filament-icon-hub Version ^0.1 | — | — |
spatie/laravel-package-tools Version ^1.92 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.