Package Health

backstage/laravel-minify-html-middleware

The project is actively releasing and has a clear organization-backed repository with tests, documentation, and a license. Maintenance is concentrated in one recent contributor, and the repository lacks security policy and scanning coverage.

Latest v5.6.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

All two recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second recent contributor is shown to share the maintenance load.

Repo commit activitycaution

The repository received two commits in the past three months, all from one active maintainer. Recent work exists, but the low activity and single active contributor limit maintenance resilience.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a meaningful part of the repository's security hygiene unverified.

Security policycaution

The repository has no security policy, so the project does not document a clear process for reporting and handling vulnerabilities.

Workflow auditcaution

All 15 analyzed action references are unpinned, weakening build reproducibility; two workflows grant top-level write access, though no dangerous triggers, untrusted checkouts, script injections, or audit findings were detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mark van Eijk

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.0 || ^11.0 || ^12.0||^13.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform