Documentation is extensive, the package has a clear MIT license, and repository tooling includes Dependabot and a security policy. One high-confidence workflow audit finding around spoofable actor checks and one unpinned action warrant some caution.
85%
Total Score
100
100
100
75
The package runs a post-autoload-dump lifecycle script, which adds install-time execution surface. No provided signal shows that this script is unsafe, so this is a limited supply-chain hygiene concern rather than a severe risk.
Both workflows were analyzed successfully, with no untrusted checkout or script-injection findings; three of four action references are pinned. However, a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow, and that workflow grants top-level write permissions, so the automation deserves review.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-661685 awcodes/filament-curator is vulnerable to Path Traversal in versions 3.0.0 - 3.7.10, 4.0.0 - 4.2.0 and 5.0.0 - 5.3.1. | 3.0.0 - 3.7.104.0.0 - 4.2.05.0.0 - 5.3.1 | Medium |
AIKIDO-2026-972512 awcodes/filament-curator is vulnerable to Cross-Site Scripting (XSS) in versions 4.0.0 - 4.1.4 and 5.0.0 - 5.1.4. | 4.0.0 - 4.1.45.0.0 - 5.1.4 | Medium |
AIKIDO-2026-878390 awcodes/filament-curator is vulnerable to Broken Access Control in versions 0.0.1 - 3.7.9, 4.0.0 - 4.1.2 and 5.0.0 - 5.1.2. | 0.0.1 - 3.7.94.0.0 - 4.1.25.0.0 - 5.1.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
league/glide Version ^3.0 | — | — |
filament/filament Version ^4.0|^5.0 | — | — |
enshrined/svg-sanitize Version ^0.22 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.