Usable with caveats: the release is licensed, tested, documented, and backed by an active organization-owned repository. Maintenance has recently slowed, with only one release in the last year and no commits or active maintainers in the last three months; workflow permissions are also not explicitly restricted.
66%
Total Score
75
100
88
90
The package is about 2 years old with 10 releases, but only 1 release occurred in the last 12 months despite a historical median interval of about 10 days. This indicates a meaningful recent slowdown.
The repository recorded zero commits and zero active maintainers in the last three months. Although a new release was published recently, the lack of sustained source activity raises maintenance and abandonment concerns.
There is only one open issue and no recent issue or pull-request activity. This is not a severe problem, but it provides little evidence of active support.
The repository uses Composer build tooling but has no detected security-scanning tools. The absence of scanning weakens security-process transparency, though it is not by itself evidence that the package is unsafe.
The only workflow lacks top-level token permissions. No write permissions were detected, but explicitly declaring restrictive permissions would provide stronger CI safety assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
stancl/tenancy Version ^3.9 | — | — |
filament/filament Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.