Ongoing support looks limited, and the automation needs tighter controls. The project is backed by an organization and includes useful release and testing evidence.
64%
Total Score
83
88
75
The package has only four releases over about three and a half years, with one release in the last year and a median interval of about 363 days. This indicates slow maintenance, though the current release is recent enough to avoid an abandonment judgment.
There were no commits and no active maintainers in the last three months. Although the repository was pushed recently and the package has a new release, the current lack of development activity lowers maintenance confidence.
Version 0.1.3 is not marked as a prerelease, but the package remains below a stable major version. That adds some compatibility uncertainty without indicating that this release is itself unstable.
All three workflows were analyzed, with no untrusted checkouts or script injection, but all nine action references are unpinned. The audit also found a high-confidence bot-condition issue and one workflow grants top-level write access, so the automation needs tightening.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/database Version ^12.0 || ^13.0 | — | — |
illuminate/contracts Version ^12.0 || ^13.0 | — | — |
tucker-eric/eloquentfilter Version ^3.6 | — | — |
spatie/laravel-package-tools Version ^1.93 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.