Usable with caveats: the package is current, licensed, tested, and backed by an active organization. However, direct commit activity was absent over three months, and its workflows use write permissions with a pull-request-target job.
72%
Total Score
88
100
94
80
One workflow uses pull_request_target, which can be risky when handling untrusted pull requests, though no untrusted checkout or script injection was detected.
No commits or active maintainers were recorded in the last three months, which is a meaningful maintenance concern, although the repository was pushed today and merged four pull requests recently.
The repository has five stars and six forks, showing limited adoption but not a health failure; popularity is supporting evidence only.
Two of three workflows grant top-level write access, and one workflow declares no top-level permissions; narrower explicit permissions would reduce CI supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
lara-zeus/spatie-translatable Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.