Package Health

tomatophp/filament-media-manager

Usable with caveats: the package is actively released, licensed, tested, and backed by a matching organization repository. However, no commits or active maintainers were recorded in the last three months, and its workflows use broad write permissions with a pull-request target workflow.

Latest 5.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

One of three workflows uses pull_request_target, which requires careful handling of untrusted pull requests; no untrusted checkout or script-injection patterns were detected, limiting the concern.

Dependency profilecaution

Six runtime dependencies, including Filament, Laravel Media Library, and related TomatoPHP components, create meaningful compatibility and maintenance coupling, though the profile is not unusually large for this integration package.

Repo commit activitycaution

No commits and no active maintainers were recorded during the last three months, which is a real maintenance-continuity concern despite the recent releases and merged pull requests.

Token permissionscaution

Two workflows declare top-level write permissions and one workflow lacks top-level permissions, leaving broader-than-necessary automation access as a transparency and containment concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Fady Mondy

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^5.0
tomatophp/filament-icons
Version ^5.0
tomatophp/console-helpers
Version ^1.1
spatie/laravel-medialibrary
Version ^11.13
filament/spatie-laravel-media-library-plugin
Version ^5.0

Weekly Downloads

Info

Last Published
8 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform