Securing Filament Plugins with Plumb Security Scores | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com) - [Home](https://www.msaied.com)
- [Projects](https://www.msaied.com/projects)
- [Articles](https://www.msaied.com/articles)
- [Certificates](https://www.msaied.com/certificates)
- [About](https://www.msaied.com#about)

           [  Contact](https://www.msaied.com#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com)
- [ProjectsCase studies](https://www.msaied.com/projects)
- [ArticlesEngineering notes](https://www.msaied.com/articles)
- [CertificatesCredentials](https://www.msaied.com/certificates)
- [AboutHow I work](https://www.msaied.com#about)
- [ContactGet in touch](https://www.msaied.com#contact)

  [Start a conversation](https://www.msaied.com#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com)
2. /
3. [Articles](https://www.msaied.com/articles)
4. /
5. [Filament](https://www.msaied.com/articles?category=filament)
6. /
7. Securing Filament Plugins with Plumb: Automated Security Scoring for PHP Packages

   [Filament](https://www.msaied.com/articles?category=filament) [PHP](https://www.msaied.com/articles?category=php) 

 Securing Filament Plugins with Plumb: Automated Security Scoring for PHP Packages
==================================================================================

 Filament has integrated Plumb, an automated PHP package security scanner, into its plugins directory. Learn how Plumb scores plugins across security, maintenance, and ecosystem health — and what to do as a maintainer.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com#person) Published 5 Oct 2026 · Updated 5 Oct 2026 · 3 min read

ShareCopy linkCopied

 ![Securing Filament Plugins with Plumb: Automated Security Scoring for PHP Packages](https://cdn.msaied.com/743/8998fac3a41451ab3fe1588194e17a43.png) 

  On this page +1. [Filament Now Has Over 1,000 Plugins — and a Security Layer to Match](#filament-now-has-over-1000-plugins-and-a-security-layer-to-match)
2. [What Is Plumb?](#what-is-plumb)
3. [How the Filament Integration Works](#how-the-filament-integration-works)
4. [What Should Plugin Maintainers Do?](#what-should-plugin-maintainers-do)
5. [Check Whether Plumb Already Scans Your Plugin](#check-whether-plumb-already-scans-your-plugin)
6. [Interpreting Your Score](#interpreting-your-score)
7. [Key Takeaways](#key-takeaways)

 Filament Now Has Over 1,000 Plugins — and a Security Layer to Match
-------------------------------------------------------------------

The Filament plugins directory recently crossed 1,000 community plugins, and that milestone comes with a practical question every Laravel developer should be asking: **how do you know which plugins are safe to install?**

Manually auditing a package — checking for open security advisories, unmerged Dependabot PRs, maintenance activity, and ecosystem signals — is thorough but tedious. It is easy to skip a step, especially when you are evaluating several plugins at once.

To address this, Filament has quietly integrated [Plumb](https://plumbphp.dev) directly into its plugins directory, giving developers an at-a-glance security signal for every listed plugin.

What Is Plumb?
--------------

Plumb, written by [Kevin Ullyott](https://kevinullyott.com), is an automated scanning tool that evaluates PHP packages across three categories:

- **Security** — active advisories, GitHub Actions pinning, and related hygiene checks
- **Maintenance** — release cadence, open issues, unmerged security PRs
- **Ecosystem health** — download trends, dependency freshness, and community signals

Plumb runs up to 15 individual checks per package and combines the results into a single numeric score. A higher score means lower risk.

At the time of writing, Plumb automatically tracks nearly **170,000 packages on Packagist**, so there is a good chance your package is already being scanned.

How the Filament Integration Works
----------------------------------

The Plumb score is now displayed directly in the Filament plugins directory UI as you browse or search. No need to leave the page.

For deeper insight, each plugin's detail page includes a **"Package health" section** that breaks down:

1. The total score across all three Plumb categories
2. A full list of which individual checks passed, failed, or were skipped

Clicking any check opens an accordion with a plain-language explanation and a "Learn more" link to Plumb's detailed documentation for that specific check.

What Should Plugin Maintainers Do?
----------------------------------

### Check Whether Plumb Already Scans Your Plugin

If your plugin is publicly listed in the Filament plugins directory, Plumb is **already running automated checks** against your repository — no action required.

If you maintain a **private or paid plugin**, you need to link your GitHub account with Plumb. Instructions are at the bottom of the [Plumb scoring page](https://plumbphp.dev/scoring).

For packages **outside the Filament ecosystem**, search for your package on the Plumb website first. If it is not already tracked, submit a request via the [Plumb homepage](https://plumbphp.dev/).

### Interpreting Your Score

- **100/100** — all checks pass; no immediate action needed.
- **Less than 100** — review the detailed results page for your plugin. Each failed check links to a dedicated page explaining: 
    - Why the check matters
    - What a passing result looks like
    - Concrete steps to fix the issue

For example, the "GitHub Actions pinned to SHA" check verifies that every third-party action reference in your CI workflows is pinned to a specific commit SHA rather than a mutable tag — a common supply-chain risk.

Key Takeaways
-------------

- Plumb provides a single numeric score covering security, maintenance, and ecosystem health for PHP packages.
- Filament now surfaces Plumb scores directly in the plugins directory, reducing the manual audit burden for developers.
- Public plugins in the directory are scanned automatically; private plugin maintainers must link their GitHub account.
- Failed checks include actionable documentation so maintainers know exactly how to improve their score.
- Plumb tracks ~170,000 Packagist packages, making it useful beyond the Filament ecosystem.
- Manual code review remains the gold standard, but Plumb gives you a strong, fast starting signal.

---

*Source: [Securing Filament plugins with Plumb — Laravel News](https://laravel-news.com/securing-filament-plugins-with-plumb)*

- [Filament](https://www.msaied.com/articles?search=Filament)
- [Security](https://www.msaied.com/articles?search=Security)
- [PHP Packages](https://www.msaied.com/articles?search=PHP%20Packages)
- [Plumb](https://www.msaied.com/articles?search=Plumb)
- [Laravel](https://www.msaied.com/articles?search=Laravel)
- [Package Health](https://www.msaied.com/articles?search=Package%20Health)

 Frequently asked questions 
---------------------------

  Does Plumb automatically scan my public Filament plugin, or do I need to set something up?If your plugin is publicly listed in the Filament plugins directory, Plumb already runs automated security checks against it — no setup required. Only maintainers of private or paid plugins need to take an extra step by linking their GitHub account with Plumb on the Plumb scoring page.

   What does a Plumb score actually measure?Plumb runs up to 15 checks across three categories: security (e.g., active advisories, GitHub Actions SHA pinning), maintenance (e.g., release cadence, unmerged security PRs), and ecosystem health (e.g., download trends, dependency freshness). The results are combined into a single numeric score that reflects the overall risk of installing the package.

   Can I use Plumb for Laravel or PHP packages that are not Filament plugins?Yes. Plumb tracks nearly 170,000 packages on Packagist. Search for your package on the Plumb website to see if it is already being scanned. If it is not, you can submit a request via the Plumb homepage to start the scan and receive a score.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleFilament v3.3.56 Released: File Hash Names and Livewire Upload Fix](https://www.msaied.com/articles/filament-v3356-released-file-hash-names-and-livewire-upload-fix)  

   On this page
-------------

1. [Filament Now Has Over 1,000 Plugins — and a Security Layer to Match](#filament-now-has-over-1000-plugins-and-a-security-layer-to-match)
2. [What Is Plumb?](#what-is-plumb)
3. [How the Filament Integration Works](#how-the-filament-integration-works)
4. [What Should Plugin Maintainers Do?](#what-should-plugin-maintainers-do)
5. [Check Whether Plumb Already Scans Your Plugin](#check-whether-plumb-already-scans-your-plugin)
6. [Interpreting Your Score](#interpreting-your-score)
7. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/742/2d02018669cdeedccb5de2efb898f0ee.png) Filament · 3 min read### Filament v3.3.56 Released: File Hash Names and Livewire Upload Fix

5 Oct 2026 ](https://www.msaied.com/articles/filament-v3356-released-file-hash-names-and-livewire-upload-fix) [ ![](https://cdn.msaied.com/741/5b55c123ad08e4d34e1f4b99ad6a428b.png)  · 3 min read### Filament v4 Schema-Based Forms, Infolists, and the Unified Schema API

5 Oct 2026 ](https://www.msaied.com/articles/filament-v4-schema-based-forms-infolists-and-the-unified-schema-api-5) [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com)
- [Articles](https://www.msaied.com/articles)
- [Certificates](https://www.msaied.com/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/sitemap.xml)
