Usable with caveats: the package is licensed, tested, documented, actively released, and backed by a matching organization repository. However, no commits or active maintainers were recorded in the last three months, so ongoing maintenance should be verified before adoption.
68%
Total Score
88
100
94
80
One pull_request_target workflow is used for Dependabot auto-merge, but no untrusted checkouts or script-injection patterns were detected; the workflow design warrants routine review without making the package unfit.
The package has existed for 999 days with 11 releases and one release in the last 12 months, showing a real release history but a relatively slow recent cadence.
No commits and no active maintainers were recorded during the last three months, which is a material maintenance concern even though the repository had five merged pull requests in the last month.
Two workflows request top-level write permissions and one workflow lacks top-level permissions, leaving broader-than-necessary CI token access as a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
tomatophp/filament-icons Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
lara-zeus/spatie-translatable Version ^2.0 | — | — |
tomatophp/filament-translation-component Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.