Healthy and suitable to use, with a small maintenance and repository-security caveat. Releases are regular, the repository is active and backed by an organization, but recent work comes from one contributor and the workflow permissions are broader than ideal.
76%
Total Score
75
94
70
One workflow uses pull_request_target, which warrants review because that trigger can be sensitive, but the scan found no untrusted checkouts or script-injection patterns.
All 2 recent commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 2 commits were made in the last 3 months by one active maintainer. Recent releases remain frequent, but the limited recent commit volume leaves less evidence of broad ongoing maintenance capacity.
The repository has no stars or forks and only 2 watchers, indicating limited external adoption. This is supporting evidence rather than a decisive health problem because release and maintenance activity are present.
The repository has no SECURITY.md policy, leaving vulnerability reporting and response expectations less transparent despite the README providing a contact address.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0|^5.0 | — | — |
illuminate/contracts Version ^12.0|^13.0 | — | — |
spatie/eloquent-sortable Version ^4.0|^5.0 | — | — |
spatie/laravel-navigation Version ^1.3 | — | — |
wotz/filament-link-picker Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.