Usable with caveats: the package is actively released, well documented, tested, licensed, and backed by a matching organization repository. However, the repository shows no commits or active maintainers in the last three months, and its automation grants write access in two workflows.
72%
Total Score
88
100
94
80
One workflow uses pull_request_target, specifically for Dependabot auto-merge, creating elevated workflow-risk exposure even though no untrusted checkout or script injection was detected.
The package has existed for 658 days with three releases, including two in the last 12 months and a release today; the long median interval of about 329 days indicates a deliberate but sparse cadence.
The repository records zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern; the recent release and four merged pull requests provide only partial compensation.
Two of three workflows declare top-level write permissions, and one workflow has no top-level permissions declaration; this is broader automation access than necessary and warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
filament/notifications Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
tomatophp/filament-alerts Version ^5.0 | — | — |
mallardduck/blade-boxicons Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.