Usable with caveats: the package is licensed, tested, documented, backed by an organization, and not deprecated or archived. Recent release activity and merged pull requests help, but no commits or active maintainers were recorded in the last three months, and its CI workflows use broad write permissions.
72%
Total Score
75
50
100
80
One workflow uses pull_request_target, but no untrusted checkouts or script injection were detected; the pattern warrants review because it can run with elevated repository context.
Six runtime dependencies are declared, including the target framework and related packages; this is a meaningful integration surface but not unusually large for a Filament plugin.
Only one registry account has publish access, which creates a publishing concentration risk, although the organization-owned repository provides some backing and makes a short registry list less concerning.
The repository recorded zero commits and zero active maintainers in the last three months. Although recent merged pull requests and a same-day push provide some counterevidence, this still indicates a meaningful short-term maintenance gap.
Two of three workflows declare top-level write permissions and one has no top-level permissions declaration. This broadens CI credential exposure compared with least-privilege configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
calebporzio/sushi Version ^2.5.4 | — | — |
filament/filament Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
tomatophp/filament-settings-hub Version ^5.0 | — | — |
mikebronner/laravel-model-caching Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.