Filament’s directory has passed 1,000 community plugins. About 50 more were added since the previous count. Direct code review remains the strongest safeguard, while security advisories and long-unmerged Dependabot pull requests provide additional risk signals. Checking these indicators manually takes time and makes omissions easy.

The directory now integrates Plumb, a tool created by Kevin Ullyott that scans PHP packages. It combines security and maintenance checks into a score, while a third category measures ecosystem health. The result appears in directory searches and on plugin pages. Each page has a “Package health” section with category scores and the status of all 15 checks, including skipped checks.

Public plugins are scanned automatically. Owners of private paid plugins must link their GitHub account to Plumb through the scoring page. Plumb also tracks almost 170,000 packages on Packagist at the time of writing. Owners of PHP or Laravel packages outside the Filament ecosystem can search for an existing result or request a scan from the Plumb homepage.

A score of 100/100 is the ideal result according to Plumb’s checks. Lower scores include details explaining each result. Filament’s Custom Dashboards plugin, for example, has nine third-party references in its GitHub Actions workflows, and all nine are pinned to specific commit SHAs. Individual check pages explain why a check matters and what success requires. They also show how to fix a failure.