Manage your documents and contracts all in one place with template builder
76%
Total Score
88
100
94
80
One workflow uses pull_request_target for Dependabot auto-merge, which requires elevated trust, but no untrusted checkout or script-injection patterns were detected across the three analyzed workflows.
The package has existed for 700 days with five releases, but only one release occurred in the last 12 months and the median interval is about 80 days, indicating a relatively slow cadence.
No commits and no active maintainers were recorded during the last three months, which is a meaningful maintenance concern despite the recent push and merged pull requests.
Two workflows grant top-level write permissions and one workflow lacks a top-level permissions declaration, leaving CI permissions broader or less explicit than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
tomatophp/filament-icons Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.