Package Health

always-open/bwt-api

It has an MIT license, tests, a changelog, release notes, and organization backing. Workflow automation has a high-confidence bot-condition finding, while the package remains pre-1.0.

Latest v0.0.6PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has six releases over about nine months, but the latest release was about six months before collection. That suggests maintenance may have slowed after an initially active period.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the past three months. This is concrete evidence of currently quiet maintenance, despite the recent release history.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence of abandonment.

Version stabilitycaution

This is a non-prerelease v0.0.6 release, but the pre-1.0 version still indicates an immature compatibility commitment.

Workflow auditcaution

All 10 analyzed action references are unpinned, and the audit found one high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this remains a workflow-hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Quentin Schmick

Direct Dependencies

DependencyLast ReleaseScore
spatie/laravel-data
Version ~4.16
—
—
illuminate/contracts
Version ~10.0||~11.0||~12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—
always-open/laravel-request-logger
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform