Package Health

abather/spatie-laravel-model-states-actions

This is a usable, licensed package with a stable major release, 13 releases over roughly 20 months, recent publication activity, a matching repository, documented usage, and repository tests and changelog coverage. The main concerns are that the repository recorded no commits or active maintainers in the last 3 months despite a recent push and release, the project is backed by a single individual, security scanning and a security policy are absent, and the workflow does not declare top-level token permissions. Its small popularity footprint is not disqualifying for a focused Laravel package, but adoption should account for the thin maintenance and security-reporting posture.

Latest 2.1.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dependency profilecaution

Five runtime dependencies, including Laravel, Filament, and Spatie model states, are material coupling for a focused integration package. The dependency set is understandable from the package description but increases compatibility and upgrade surface.

Lifecycle scriptscaution

A post-autoload-dump lifecycle script is present. This adds install-time execution surface, but the signal does not indicate a dangerous script or explain behavior severe enough to make the package unfit.

Maintainerscaution

Only one registry account has publish access. That is a genuine continuity risk for an individually backed package because release capacity may depend on one person.

Project backingcaution

The repository is owned by a User account rather than an organization, so there is no organizational backing signal to compensate for the single-maintainer model.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last 3 months. Although a recent push and current release show some activity, the absence of recent commit activity weakens confidence in ongoing maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mohammed Aljuraysh

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.0||^5.0
illuminate/contracts
Version ^13.0||^10.0||^11.0||^12.0
spatie/laravel-model-states
Version ^2.0
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
13 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform