The package has a clear README, tests, changelog, MIT licensing, and a repository that matches the package. Its lack of releases and commits for about two years raises maintenance risk, so pinning this version is prudent.
55%
Total Score
38
100
83
75
There were no commits and no active maintainers in the last three months, consistent with the long release gap and indicating likely maintenance stagnation.
A post-autoload-dump lifecycle script runs during installation. This is an additional execution surface and warrants caution, although the signal does not show that the script is harmful.
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is no provided evidence of a broader publishing or maintenance base.
The package and repository are both associated with the same individual user context, and the repository owner is not an organization. This supports identity continuity but not a broad project backing structure.
The package is about two years old but has only three releases, with no releases in the last 12 months. That materially lowers confidence in ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0 | — | — |
illuminate/contracts Version ^10.0 || ^11.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.