Package Health

anthonyedmonds/govuk-laravel

This is a healthy, actively maintained release with a strong publication history: 124 releases over roughly 4.3 years, 37 releases in the last 12 months, and a median release interval of about 4.7 days. Version 8.6.0 is stable, non-prerelease, not deprecated, clearly licensed under MIT, and supported by a substantial artifact containing tests, documentation, and build metadata. Repository activity is strong, with 43 commits and five merged pull requests in the last three months, although all recent commits come from one maintainer. The lack of a security policy and explicit workflow token permissions are transparency and hardening gaps, but the analyzed workflow shows no dangerous workflow patterns, and there are no install-time lifecycle scripts. This package appears suitable to depend on, with normal single-maintainer bus-factor risk.

Latest 8.6.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a genuine operational concentration risk, though the repository shows that the same maintainer is actively producing releases and commits.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational succession evidence to offset the single-maintainer concentration.

Repo bus factorcaution

One contributor made all 43 commits in the last three months, creating a meaningful bus-factor and continuity risk for this user-owned project.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is adequate, while automated security coverage is a modest gap.

Security policycaution

No repository security policy was found, reducing vulnerability-reporting transparency and maintenance readiness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Anthony Edmonds

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^13
—
—
nunomaduro/laravel-mojito
Version ^0
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform