Package Health

always-open/oxylabs-api

This release appears generally suitable to depend on: it is not deprecated or archived, has a matching repository with an organization owner, a clear MIT license, tests, changelog, security policy, and substantial release activity. Maintenance is recent but relatively light, with only 2 commits from 2 contributors in the last 3 months, and the package remains below a stable major version. The zero-star repository is only supporting evidence, not a decisive concern, while the install-time script and broad GitHub Actions write permissions merit review before use in a high-assurance environment.

Latest v0.8.8PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target, which can be security-sensitive, but no untrusted checkout or script-injection patterns were detected across the four analyzed workflows.

Lifecycle scriptscaution

A post-autoload-dump install-time lifecycle script is present. This is an additional execution surface and warrants inspection, although the signal does not establish that the script is unsafe.

Repo commit activitycaution

Only 2 commits occurred in the last 3 months, indicating light recent development. Both activity and contributor counts are nonzero, so this is a maintenance caution rather than a severe abandonment signal.

Repo popularitycaution

The repository has zero stars, forks, and watchers, which provides no external adoption evidence. Popularity is supporting evidence only, so this modestly limits confidence rather than indicating abandonment by itself.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanner is a transparency and assurance gap, not evidence that the package is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Quentin Schmick

Direct Dependencies

DependencyLast ReleaseScore
spatie/laravel-data
Version ~4.16
—
—
illuminate/contracts
Version ~10.0||~11.0||~12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—
always-open/laravel-request-logger
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform