Package Health

amzad/laravel-purchasable

Healthy and reasonable to adopt, with some early-project caveats. It has active recent development, a stable release, tests and CI in the repository, but the project is only 59 days old and maintenance is concentrated in one main contributor.

Latest v3.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target, which warrants review because that trigger can expose elevated repository context. However, the scan found no untrusted checkout or script-injection patterns.

Lifecycle scriptscaution

The package uses a post-autoload-dump install lifecycle script. This adds installation-time behavior that deserves review, but it is not severe on its own and no other supplied signal indicates that the script is unsafe.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the concentrated contributor activity and single registry maintainer represent the actual available maintenance base. Recent commits partly compensate for that limited backing.

Repo bus factorcaution

Two contributors were active, but the leading contributor made 80% of recent commits. The second contributor provides some continuity, while the concentration still creates a moderate maintenance risk for a user-owned project.

Security policycaution

The repository has no security policy. That reduces transparency about vulnerability reporting and response, though it does not by itself indicate abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

amzad78692

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.0||^11.0||^12.0
spatie/laravel-model-states
Version ^2.12
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
1 month ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform