Filament nestedset tree builder powered by kalnoy/nestedset with Filament v4 and v5 support
84%
Total Score
80
100
100
70
One of five workflows uses pull_request_target, which warrants review because that trigger can elevate workflow privileges; no untrusted checkout or script-injection findings were detected, limiting the concern.
The package uses a post-autoload-dump install-time script, which adds execution and supply-chain surface; the signal does not show that the behavior is malicious, so this is a review item rather than a health verdict.
Only one account has registry publish access, creating some operational concentration; however, registry access records do not measure actual maintenance, and the repository shows two active contributors and recent releases.
The source repository is owned by a personal user account rather than an organization, so the small maintainer base has less institutional handoff support; balanced recent contributions partly mitigate this risk.
Three workflows declare top-level write permissions and two omit top-level permissions, leaving broader-than-necessary or unclear token scope in parts of the CI configuration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kalnoy/nestedset Version ^6.0 || ^7.0 | — | — |
filament/filament Version ^4.0 || ^5.0 | — | — |
spatie/laravel-package-tools Version ^1.15.0 | — | — |
codewithdennis/filament-select-tree Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.