Securing Filament plugins with Plumb

Article General
Alex Six avatar Author: Alex Six
Published: Sep 28, 2026

If you keep up with Filament news, you've likely already heard that we just passed over 1,000 community plugins in the Filament plugins directory! So with over one-thousand plugins and growing (in the time since we published that article, we've already added another 50 community plugins), it's about time we talked about plugin security and how we're already adding security layers to help you make informed decisions about what plugins to install.

#Filament plugin security

It should go without saying that, regardless of any security metrics you might see for a package that you want to pull into your application, reviewing the code yourself will forever be the best way to ensure that you aren't including code that you don't know about.

But outside of reviewing the code yourself, there are other indicators that you can use to gauge the risk, such as checking for active security advisories, looking for Dependabot PRs that have been left open for long spans of time, among many others. These sorts of indicators give you a great, up-front feel for if the package you're looking at (or the package you already have installed) is a secure choice. Why dive deeper into how a plugin works when you already know that security fix patches aren't getting merged in, 100 security advisories already exist for the package, or it's entirely unmaintained?

However, as good as all of these checks are, they all have the same basic issue: the list is tedious, can take a long time, and it is very easy to forget one or two of the things you originally wanted to check!

Because of that, Filament quietly rolled out a new plugin directory integration built specifically to give you a head-start and perform many of these checks for you and display the results front and center on the plugins directory page.

#Plumb

Written by Kevin Ullyott, Plumb is a relatively new tool that automatically scans PHP packages and scores them based on security, maintenance, and overall ecosystem health. Once a package is scanned, Plumb combines all of its checks and spits out a single number that can be used to determine the risk level for installing that package.

Our integration with Plumb makes it quick and easy to see the Plumb security score right in the UI for all plugins in the plugins directory as you scan or search.

Want more information about why a given plugin received a specific score? On the details page for each plugin, we have added a "Package health" section that shows you the total score for each of the three Plumb security categories (security, maintenance, and ecosystem) as well as a full breakdown of which of the 15 checks passed, failed, or were skipped.

#How to handle security checks as a maintainer?

#Getting a Plumb score for your repository

Plumb and Filament have come together to make staying up-to-date with security checks as simple as possible for all Filament plugin maintainers.

First, if your plugin is already publicly available on the Filament plugins directory, you're in luck, because Plumb is already running automated security checks against your repository!

Secondly, if you have a private, paid plugin on the plugins directory though, you will need to take one more step and link your Github account with Plumb. You can do that in a few quick steps found on the bottom of the "scoring" page on Plumb's website.

Finally, if you are the proud owner of a PHP and/or Laravel package repository outside of the Filament ecosystem and would still like to have Plumb score your package's security, there is an option available for you as well! Plumb automatically tracks almost 170,000 packages on Packagist (at the time of writing), so before you request your package, search for it on the Plumb website. Odds are fairly high that Plumb is already scanning and scoring your repository. However, if Plumb has not already scanned your package, you can use the request form on the Plumb homepage to start the scan and get your score.

#What to do with a Plumb score

So you've gotten your Plumb security score. Now what?

Let's start with the easy path: did you get a 100/100? If so, you're good to go.

With that out of the way, what happens if you get less than a perfect score? It's ok, there's no need to panic. For every plugin that Plumb scores, it provides a detailed readout that shows how Plumb decided upon the overall score as well as the score for each section. You can see the results page for Filament's Custom Dashboards plugin, here, if you'd like to follow along.

When you visit your plugin's result page, you can click on any of the checks that were performed and see specific details about how your plugin earned a pass or a fail. For example, again using Filament's Custom Dashboards plugin, we can click on the "GitHub Actions pinned to SHA" check to see that, out of our nine third-party references within our Github Actions, all nine of them are securely pinned to a specific commit SHA.

In this same accordion UI element, you can drop open the small "How this check works" section for some quick information, or you can click the "Learn more about this check" link to be taken to an extremely detailed description of the check, why it matters, what a successful check looks like, and how to do it. Again, we'll use the "GitHub Actions pinned to SHA" check as an example: see it here. If you have specific checks that aren't passing and you aren't quite sure how to fix them, these pages are an absolute gold mine.


The Filament team is so excited to have partnered with Plumb and be able to give everyone, maintainers and users alike, another signal to help secure their packages and applications. And obviously, it goes without saying, we want to say a massive thank-you to Plumb for partnering with us to help us achieve this goal!

Happy building!

The author

Alex Six avatar Author: Alex Six

Alex is a full-stack developer from South Carolina, USA. He is a Senior Software Development Engineer at Zillow and the Head of Developer Relations for Filament. Alex spends his time creating content about Filament & Laravel to help other developers level-up their development game! He also has an adorable corgi and uses Vim, by the way!

Articles
19

From the same author