Usable with caveats: the package is well documented, tested, licensed, and backed by an active organization, but its release history is sparse and there were no commits in the last three months. Review its ongoing maintenance before making it a core dependency.
68%
Total Score
88
100
94
80
One of three workflows uses pull_request_target, but no untrusted checkout or script injection was detected; this warrants review rather than a severe health penalty.
Only 3 releases have been published across 688 days, with just 1 release in the last 12 months and a median interval of about 344 days; this is a meaningful sign of slow maintenance, though a recent release exists.
The repository had 0 commits and 0 active maintainers in the last 3 months, which is the strongest maintenance concern; recent merged pull requests and the latest release provide only partial compensation.
Two workflows request top-level write permissions and one lacks top-level permissions, including the Dependabot auto-merge workflow; this is a workflow-hygiene concern, though no direct exploitation pattern was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
stichoza/google-translate-php Version ^5.3 | — | — |
tomatophp/filament-translations Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.