A Laravel Filament package to manage pages.
70%
Total Score
caution
Usable with caveats: maintenance is concentrated in one contributor despite active releases and organizational backing.
The package runs a post-autoload-dump install-time script, which adds execution during Composer installation. No provided signal shows that this hook is harmful, so it is a limited supply-chain hygiene concern rather than a severe risk.
All 3 recent commits came from one contributor, giving the project a concentrated operational dependency. Organizational ownership provides some handoff capacity, but no second active contributor is shown.
The repository had 3 commits in the last 3 months, showing continued work, but the volume is modest for a package with active releases. This is a mild maintenance concern.
Both workflows were analyzed successfully with no audit findings, all 5 action references are pinned, and one workflow uses read-only permissions. One workflow has top-level write permissions, which is a mild excess but not dangerous without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.0 | ^5.0 | — | — |
novius/laravel-meta Version ^1.2.0 | — | — |
novius/laravel-linkable Version ^2.0.0 | — | — |
spatie/laravel-sluggable Version ^3.4 | ^4.0 | — | — |
novius/laravel-json-casted Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.