Package Health

ambrosethebuild/laravel-installer

It has a clear README, MIT licensing, recent releases, and ongoing commits from two contributors. The install-time script and absent security policy merit extra review before adoption.

Latest 1.1.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump script runs during installation, which expands install-time behavior and warrants review even though no maliciousness judgment is being made here.

Project backingcaution

The repository is owned by the same individual as the registry namespace, so there is no organizational backing to offset the concentrated contributor base.

Repo bus factorcaution

Two contributors are active, but the top contributor made about 71% of recent commits, leaving maintenance somewhat concentrated in a user-owned project.

Security policycaution

The repository has no security policy, which reduces transparency about how vulnerabilities should be reported and handled.

Workflow auditcaution

The audit covered both workflows with no reported findings or untrusted checkouts, but all five action references are unpinned and one workflow grants top-level write permission, creating avoidable workflow supply-chain and permission hygiene gaps.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ambrose Bako

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.0||^11.0||^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform