Package Health

artisanpack-ui/pagespeed-insights

The project is only 43 days old, so its long-term stability is not yet demonstrated. Its organization backing, 36 commits in three months, release notes, tests, and documentation provide meaningful support, despite missing security policy and unpinned workflow actions.

Latest v1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is a very new package, released only once and 43 days ago, so there is little release history to establish long-term maintenance consistency.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool is reported. The missing scanner is a transparency and hygiene gap, not evidence of unsafe code by itself.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response procedures unclear.

Workflow auditcaution

Both workflows use read-only permissions and the audit completed fully with no untrusted checkout or script-injection findings. However, all 13 action references are unpinned; the cache-poisoning findings are low-confidence hygiene warnings, so this lowers confidence in build reproducibility but is not a severe risk alone.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jacob Martella

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.5
illuminate/support
Version ^12.0|^13.0
artisanpack-ui/core
Version ^1.0
illuminate/database
Version ^12.0|^13.0
artisanpack-ui/hooks
Version ^1.2

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform