It has clear licensing, useful documentation, repository tests, and dependency security tooling. Workflow permissions, an unpinned action set, and a high-confidence bot-condition finding add avoidable supply-chain maintenance risk.
48%
Total Score
50
79
100
The package has only one release, published 430 days ago, with no releases in the last 12 months. That is a strong maturity and abandonment concern for a dependency with no demonstrated release cadence.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this materially raises the risk that fixes and compatibility updates will not arrive.
The linked repository is not archived, which preserves the possibility of future maintenance. Its last push was 430 days ago, so the non-archived status only partly compensates for the inactivity.
All 12 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. There are also three workflows with top-level write permissions; the absence of an untrusted checkout or script-injection sink keeps this from being a severe workflow verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/forms Version ^3.0|^4.0 | — | — |
illuminate/contracts Version ^10.0|^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.