Package Health

angel-source-labs/laravel-expression-grammar

Usable with caveats: the package is small, licensed, tested, and backed by an organization, but it has had no release or repository activity for almost two years. Its limited adoption and missing security workflow documentation add maintenance and transparency concerns.

Latest v1.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

Only two releases have been published, with no release in the last 12 months and an interval of about 20 months between releases. That may be reasonable for a small stable helper, but it lowers evidence of ongoing maintenance.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, with the repository last pushed almost two years ago. For a small utility this may reflect stability, but it leaves little evidence that issues or compatibility changes are being handled.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, indicating very limited visible adoption. Popularity is only supporting evidence, so this adds caution rather than making the package unfit by itself.

Repo toolingcaution

The repository uses Composer for builds, but no security scanning tooling was detected. This is a transparency gap, though the absence of scanning alone is not severe for this small package.

Repository archivedcaution

The linked repository is not archived, although its last push was almost two years ago. The active repository status is reassuring, but the old last-push date is consistent with the maintenance concern shown by release history.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Brion Finlay

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version >=5.8
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform