Clear documentation, tests, and release notes make integration easier. The organization-backed repository and security policy provide useful support despite limited recent activity.
68%
Total Score
67
100
88
88
The package is young at 147 days old with three releases and a median interval of about 33 days; this shows activity but limited long-term history.
One contributor made all two recent commits, creating a thin operational base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only two commits were made in the last three months, indicating limited recent maintenance activity even though the repository was pushed recently.
Composer build tooling is present, but no security scanning tools were detected; the repository's separate security policy partly offsets this transparency gap.
All five workflows were analyzed, but all 12 action references are unpinned, two workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a hygiene and workflow-safety concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/contracts Version ^11.0|^12.0|^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.