The package includes clear documentation, repository tests, a changelog, matching MIT licensing, and a repository that clearly belongs to it. GitHub Actions use four unpinned actions, and the repository has no security policy or security scanning, leaving avoidable hygiene gaps.
68%
Total Score
50
100
88
63
A post-autoload-dump install script is present. This is a meaningful install-time behavior to review, but the signal alone does not show that it is unsafe or unusually broad.
The registry lists one maintainer, which leaves a thin publishing base for a user-owned project. The repository's tests and documentation provide some compensation but do not establish maintainer redundancy.
The repository is owned by an individual account rather than an organization, so there is no organizational backing signal to offset the thin maintainer base.
Only two releases exist, both published within hours on a package that is effectively new, so there is not yet enough history to demonstrate sustained maintenance or release stability.
No commits are recorded in the preceding three months, but the repository was pushed within hours of this assessment and the package is newly published, making this a limited-history concern rather than evidence of a collapsed project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.