Usable with caveats: the package is licensed, tested, documented, actively released, and backed by an organization. Commit activity has been absent for three months, while workflow permissions and a pull-request automation workflow add modest maintenance and supply-chain concerns.
72%
Total Score
88
100
89
80
One of three workflows uses pull_request_target for Dependabot auto-merge; no untrusted checkouts or script injection were detected, so the workflow configuration warrants caution but is not severe on its own.
The package has existed for 658 days with three releases and two releases in the last 12 months; this shows ongoing publishing but a relatively slow release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is a real maintenance concern despite a recent push and five merged pull requests.
The repository has only 2 stars, 1 fork, and 1 watcher, so external adoption and review are limited; this is supporting evidence rather than a standalone health failure.
Two workflows declare top-level write permissions and one workflow lacks top-level permissions, leaving broader automation access than ideal and increasing workflow-governance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
filament/notifications Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
tomatophp/filament-alerts Version ^5.0 | — | — |
mallardduck/blade-boxicons Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.