Tests, a changelog, and a security policy improve transparency. The small project has limited recent activity and all four recent commits came from one contributor, so continuity depends heavily on that maintainer.
78%
Total Score
50
100
75
A post-autoload-dump install-time script adds some execution-surface risk, although only one lifecycle script is declared and no stronger evidence of unsafe behavior is provided.
The repository and registry are owned by the same individual account, so the single-maintainer concentration is not offset by organization-level backing.
One contributor made all four commits in the last 3 months, concentrating maintenance knowledge and creating a meaningful continuity risk.
Four commits in the last 3 months show ongoing work, but the activity is modest for an integration plugin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-data Version ^4.0 | — | — |
illuminate/contracts Version ^11.0|^12.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.