Recent releases are frequent, with five active contributors and a clear MIT license. The source repository is maintained by an organization, but its package identity is not clearly established and its automated workflow has a high-confidence bot-condition finding.
42%
Total Score
100
75
75
Packagist marks the entire package abandoned and names backstage/mails as its replacement. This is a substantial dependency risk even though the release history and repository activity are strong.
The linked repository is named mails rather than vormkracht10/filament-mails and its README does not mention this package. That leaves package ownership and provenance less clear than expected.
All five workflows were analyzed and all 12 action references are pinned, but a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Top-level write permissions in three workflows add moderate hygiene concern, although no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
backstage/laravel-mails Version self.version | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.