Package Health

alexvergara/laravel-aws-timestream

The package includes tests, a changelog, and a focused repository, but its early-stage release remains unproven. Unpinned workflow actions add supply-chain hygiene risk; pin this version only with plans to maintain or replace it.

Latest v0.0.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

This package has only one release, v0.0.1, published about four years ago, with no releases in the last 12 months. That is strong evidence of an unmaintained or unfinished dependency.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, after roughly four years since the last push. This is the clearest abandonment concern for depending on the package.

Project backingcaution

The registry namespace and repository are owned by the same individual user, which is consistent ownership but provides no organizational backing to compensate for the thin maintenance record.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal to offset the lack of maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a minor transparency and hygiene gap, not a standalone dependency blocker.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alex Vergara

Direct Dependencies

DependencyLast ReleaseScore
aws/aws-sdk-php
Version ^3.209
illuminate/support
Version 5.6.*

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform