Easy authorization system for filament, with advanced features to inject permissions from different places.
64%
Total Score
67
100
100
50
Only one registry account has publish access, which reduces publishing redundancy; the frequent release history provides some compensation but does not remove the single-publisher risk.
The repository records zero commits and zero active maintainers over the last three months, a maintenance concern despite the recent release and push activity.
No repository security policy was found, leaving disclosure and response guidance undocumented for a security-sensitive authorization package.
All workflows were analyzed, but all six action references are unpinned. A high-confidence bot-conditions finding affects the Dependabot auto-merge workflow, and two workflows grant top-level write permissions; the pull_request_target workflow has no untrusted checkout or script-injection sink, limiting the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^4.1|^5.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-permission Version ^6.21|^7.2.4 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
timo-de-winter/filament-modifiable-plugins Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.