A Filament field for the redactor WYSIWYG editor.
70%
Total Score
50
100
100
50
The repository is owned by an individual rather than an organization, so the concentrated maintainer and contributor activity represents a genuine single-person continuity risk.
One contributor made all commits in the last three months, so maintenance is fully concentrated in a single person. The recent release and active repository partly offset, but do not remove, this continuity risk.
Only two commits were made in the last three months by one active maintainer. Recent activity is positive, but the low volume limits evidence of sustained maintenance capacity.
No security policy was found. This is a transparency gap for reporting vulnerabilities, though it is less severe for a small field package than for security-sensitive infrastructure.
The audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, all six action references unpinned, and top-level write permissions in two workflows. No untrusted checkout or script injection was found, which limits the impact but leaves meaningful workflow hygiene and control concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.3||^4.0||^5.0 | — | — |
illuminate/contracts Version ^13.0||^12.0||^11.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.