Package Health

bagistoplus/visual

The MIT license, tests, release notes, and recent repository work provide useful support. Treat the alpha-only release stream, concentrated contribution, and unpinned workflow actions as reasons to pin and test carefully.

Latest v2.0.0-alpha.31PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script, which adds execution during installation and warrants attention, though this is common for framework packages.

Repo bus factorcaution

One contributor made about 85% of recent commits, creating concentration risk; the organization-owned project provides some handoff capacity but does not remove the narrow active contributor base.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Version stabilitycaution

The assessed release is an alpha and all recent releases are prereleases, so the package may change incompatibly even though development is active.

Workflow auditcaution

All seven workflows were analyzed with no audit findings or untrusted-code sinks, but all 18 action references are unpinned and three workflows grant top-level write permissions; these are workflow hygiene concerns rather than severe risks here.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eldo Magan

Direct Dependencies

DependencyLast ReleaseScore
mews/purifier
Version ^3.4
craftile/laravel
Version ^0.11.0
spatie/browsershot
Version ^3.61||^5.0
symfony/filesystem
Version ^6.4 || ^7.0 || ^8.0
bagistoplus/couleur
Version ^0.2.0

Weekly Downloads

Info

Last Published
12 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform