Package Health

artisanpack-ui/apple-oauth

The MIT license, detailed README, release notes, and active repository work improve transparency. Its small maintenance base and workflow pinning need attention before making it a core dependency.

Latest v1.0.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is the first release and the package is only 0 days old, so there is no historical evidence of sustained maintenance or release stability yet.

Repo bus factorcaution

All 10 recent commits came from one contributor, creating a narrow maintenance base. Organization backing provides some handoff capacity, but no second active contributor is shown.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tool was detected, leaving a modest transparency and maintenance gap for an OAuth package.

Security policycaution

The repository has no security policy, which is a transparency gap for a package handling OAuth credentials and token storage.

Workflow auditcaution

All 16 analyzed action references are unpinned, so workflow inputs can change unexpectedly. The reported cache-poisoning finding has low confidence and is hygiene at most; the audit otherwise found no untrusted checkout or script-injection path.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jacob Martella

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^10.0|^11.0|^12.0|^13.0
artisanpack-ui/core
Version ^1.0
artisanpack-ui/hooks
Version ^1.2

Weekly Downloads

Info

Last Published
5 hours ago
Created
5 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform