Usable with caveats: the package is actively released, licensed, tested, and backed by a matching organization repository. However, no commits or active maintainers were recorded in the last three months, and its workflows use broad write permissions with a pull-request target workflow.
68%
Total Score
88
50
100
80
One of three workflows uses pull_request_target, which requires careful handling of untrusted pull requests; no untrusted checkout or script-injection patterns were detected, limiting the concern.
Six runtime dependencies, including Filament, Laravel Media Library, and related TomatoPHP components, create meaningful compatibility and maintenance coupling, though the profile is not unusually large for this integration package.
No commits and no active maintainers were recorded during the last three months, which is a real maintenance-continuity concern despite the recent releases and merged pull requests.
Two workflows declare top-level write permissions and one workflow lacks top-level permissions, leaving broader-than-necessary automation access as a transparency and containment concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
tomatophp/filament-icons Version ^5.0 | — | — |
tomatophp/console-helpers Version ^1.1 | — | — |
spatie/laravel-medialibrary Version ^11.13 | — | — |
filament/spatie-laravel-media-library-plugin Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.