Package Health

bagistoplus/basic-blocks

Healthy and suitable to use, with a small maintenance risk. The package is actively releasing, tested in its repository, licensed, and backed by an organization, but all recent commits come from one contributor and workflow permissions are broader than ideal.

Latest v1.6.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One of five workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger has elevated context, but no untrusted checkout or script-injection patterns were detected.

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This is a meaningful installation behavior to review, although the signal does not show a harmful script or unusually broad action.

Repo bus factorcaution

One contributor made all 18 commits in the last 3 months, creating a real continuity risk; organization ownership partly compensates because maintenance can potentially be handed off.

Repo popularitycaution

The repository has no stars, forks, or watchers, so there is little external adoption evidence; this is only supporting evidence and does not outweigh the strong release and commit activity.

Security policycaution

No security policy is present, leaving vulnerability-reporting expectations less transparent for users of this package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eldo Magan

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0||^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform