A Full featured CMS plugin for Filament PHP
55%
Total Score
caution
Usable with caveats: three months without commits and risky, unpinned automation weaken confidence in ongoing maintenance.
All five workflows were analyzed, but all 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. Three workflows also grant top-level write permissions; although no untrusted checkout or script injection was found, this weakens automation integrity.
The package runs a post-autoload-dump install-time script. This adds execution during installation and warrants some caution, although the signal does not show that the script is harmful.
Only one account has registry publish access. Because the repository is user-owned rather than organization-owned, this indicates a thin visible publishing and maintenance base.
The source repository is owned by an individual user, not an organization, so there is no observed organizational backing to offset the single registry maintainer and recent inactivity.
The package is about 309 days old and has 10 releases, but all 10 occurred within the last 12 months with a very short median interval, indicating a concentrated early release burst rather than a demonstrated long-term cadence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^3.0|^4.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.