Package Health

astrotomic/laravel-github-sponsors

Latest 1.2.0PackagistPackagist

76%

Total Score

healthy

Healthy: a recent release from an organization-backed project outweighs its single-contributor maintenance and unpinned workflow actions.

Health Score Breakdown

Repo bus factorcaution

One contributor made all recent commits, concentrating maintenance responsibility; organization backing provides some ability to hand work off but does not remove the concentration.

Repo commit activitycaution

Only one commit was recorded in the last 3 months, indicating limited recent development activity despite the recent release.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.

Workflow auditcaution

Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 4 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tom Witkowski

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—
guzzlehttp/guzzle
Version ^7.0.1
—
—
illuminate/support
Version ^9.0 || ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform