Usable with caveats: the package is actively published, well documented, tested, licensed, and backed by a matching organization repository. However, direct commit activity was absent over the last three months and only two releases arrived in the past year, so ongoing maintenance should be watched.
72%
Total Score
88
100
94
80
One workflow uses pull_request_target for Dependabot auto-merge, which carries elevated workflow trust requirements, but no untrusted checkout or script-injection patterns were detected.
Thirty releases over 879 days show an established project, but only two releases in the last year indicate a comparatively slow recent release cadence.
No commits and no active maintainers were recorded during the last three months. This is a meaningful maintenance concern, although the recent release, current push timestamp, and five merged pull requests provide partial compensating evidence.
Two of three workflows declare top-level write permissions and one declares no top-level permissions. This broadens CI token authority and warrants review, though the signal does not show an exploitable workflow pattern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
maatwebsite/excel Version ^3.1.64|^4.0 | — | — |
tomatophp/filament-types Version ^5.0.1 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
lab404/laravel-impersonate Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.