Usable with caveats: the package is licensed, documented, tested, actively released, and backed by a matching organization repository. However, the repository shows no commits or active maintainers in the last three months, and its automation grants broad write permissions in places, so verify ongoing maintenance before adopting it for important billing workflows.
68%
Total Score
88
100
94
80
One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection patterns were detected, but this workflow type warrants review because it can operate with elevated repository context.
The package has existed for about two years, with nine releases and two releases in the last 12 months; this indicates ongoing publication but a relatively modest recent cadence.
The repository records zero commits and zero active maintainers in the last three months despite a recent push and release, leaving a meaningful concern about sustained maintenance capacity.
Two of three workflows declare top-level write permissions, and one workflow lacks top-level permissions entirely. This is broader automation privilege than ideal and increases repository-maintenance risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
barryvdh/laravel-dompdf Version ^3.0 | — | — |
tomatophp/filament-types Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
tomatophp/filament-locations Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.