Package Health

avexsoft/filament-donkey

The smart-ass Filament plugin to manage `config()` in production

Latest 1.0.15PackagistPackagist

76%

Total Score

healthy

Frequent releases and recent commits support adoption, but the workflows use unpinned container images.

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install-time script runs during Composer installation. This is a supply-chain exposure that warrants caution even though no malicious behavior is established here.

Repo popularitycaution

The repository has 3 stars and no forks, so community validation is limited; this is supporting evidence only and does not outweigh the active release and commit history.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency gap.

Security policycaution

The repository has no security policy, making vulnerability reporting and response expectations less clear.

Workflow auditcaution

All 3 workflows were analyzed and have no untrusted checkouts or script injection, but all 8 action references are unpinned and the audit found a high-confidence high-severity unpinned container image.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

avexsoft

Direct Dependencies

DependencyLast ReleaseScore
avexsoft/donkey
Version ^1
—
—
filament/filament
Version ^4
—
—
composer/installers
Version ^2.3
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform