A Laravel Filament package for news and blog posts management
72%
Total Score
83
100
50
A post-autoload-dump install-time script runs during Composer setup. This is not inherently unsafe, but it adds execution during installation and warrants attention.
Only one commit was recorded in the last three months, indicating very light recent development. The recent release provides some compensating evidence, but ongoing maintenance capacity remains uncertain.
The repository has no security policy, reducing transparency about how dependency issues and vulnerability reports should be handled.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all six action references are unpinned. That leaves the build exposed to changing action revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | ^5.0 | — | — |
novius/laravel-meta Version ^1.2.0 | — | — |
novius/laravel-linkable Version ^2.0.0 | — | — |
spatie/laravel-sluggable Version ^3.4 | ^4.0 | — | — |
novius/laravel-filament-slug Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.