Package Health

artisan-toolbox/core

This release is usable and shows good transparency and repository hygiene: it is MIT-licensed, non-deprecated, backed by a matching organization-owned repository, includes a README and changelog, has repository tests, security policy, Dependabot, and read-only workflow permissions. However, it is very young at 17 days with only two releases, and all 10 recent commits come from one contributor, leaving limited evidence of long-term maintenance and a notable bus-factor concern. The package artifact also runs a post-autoload-dump lifecycle script, which warrants review, although the available workflow and security signals are reassuring.

Latest 1.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

The package has three runtime dependencies, including PHP, illuminate/support, and inertiajs/inertia-laravel; this is a meaningful integration surface but not an unusually large runtime dependency set.

Lifecycle scriptscaution

A post-autoload-dump install-time script is present, adding execution complexity during dependency installation; the signal does not show that it is unsafe, so this is a review item rather than a severe risk.

Release historycaution

The package is only 17 days old and has two releases separated by about 17 days, providing very limited evidence of sustained maintenance or release discipline.

Repo bus factorcaution

One contributor made all 10 recent commits, producing a 100% top-contributor share and a clear continuity risk; organization ownership partly mitigates handoff concerns but does not remove them.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity is not decisive for a small, newly released package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Allan Mariucci Carvalho

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^13.0
inertiajs/inertia-laravel
Version ^3.0

Weekly Downloads

Info

Last Published
17 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform