Package Health

andriichuk/laravel-bsg-sms-channel

The package includes tests, a README, a changelog, and Dependabot scanning. GitHub automation has a high-confidence bot-condition issue, broad write permissions in three workflows, and all 12 action references are unpinned.

Latest v0.1.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is the first release, published 0 days ago, so there is no release track record or demonstrated maintenance cadence yet.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months, but the repository and release were created today, so this is limited evidence rather than established abandonment.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance undocumented; this is a minor transparency gap for a new package.

Version stabilitycaution

Version v0.1.0 is an initial pre-1.0 release, which signals a less mature API and greater change risk than a stable major release.

Workflow auditcaution

The audit found a high-confidence bot-condition issue, all 12 action references are unpinned, and three workflows grant top-level write access. No untrusted checkout or script-injection sink was found, so these are workflow hygiene concerns rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Serhii Andriichuk

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.9||^8.2
—
—
illuminate/contracts
Version ^11.0||^12.0||^13.5
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform