Package Health

bekwoh/laravel-media-secure

The package includes tests, release notes, a clear license, and an organization-backed repository. Repository activity has been quiet for nearly six months, while all 16 workflow actions are unpinned.

Latest 3.3.0PackagistPackagist

32%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and points to a replacement location, which is a major adoption and continuity risk even though the repository remains available.

Release historycaution

The package has existed for nearly four years with 18 releases, but only two releases in the last 12 months and a latest release nearly six months ago indicate a modest cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months; combined with the older latest push, this weakens evidence of ongoing maintenance.

Security policycaution

The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities; this is a transparency gap for a package focused on secure media access.

Workflow auditcaution

All five workflows were analyzed with no reported high-confidence findings or untrusted checkout sinks, but all 16 action references are unpinned, leaving the build exposed to moving action versions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nasrul Hazim Bin Mohamad

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0 | ^12.0 | ^13.0
—
—
cleaniquecoders/traitify
Version ^1.1
—
—
spatie/laravel-medialibrary
Version ^10.5 | ^11.5
—
—
spatie/laravel-package-tools
Version ^1.14.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform