The release is new, with only one registry release and no commits recorded in the last three months. The repository has tests, release notes, security scanning, and a policy, but its workflows use all seven actions without pinning and contain a high-confidence bot-condition finding.
68%
Total Score
75
94
83
This is the package's first and only release, published 0 days ago, so there is no release track record yet; the active repository and substantial release notes provide some context but not maturity evidence.
No commits or active maintainers were recorded in the last three months. The recent push and four merged pull requests in the last month show some activity, but the measured commit window is still thin.
All three workflows were analyzed, but all seven action references are unpinned and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is workflow hygiene risk rather than a severe standalone dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
tomatophp/filament-icons Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.