Package Health

bernskiold/laravel-currency-converter

The package includes tests, a changelog, a license, and security tooling. Its GitHub workflows use unpinned actions and contain a high-confidence bot-condition warning.

Latest 1.0.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is a young package, 107 days old, with only one release and no established release cadence. That limits evidence of long-term maintenance but does not indicate abandonment by itself.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern for a package with only one release.

Workflow auditcaution

All 11 action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bernskiold
Erik Bernskiöld

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^11.0 || ^12.0 || ^13.0
illuminate/support
Version ^11.0 || ^12.0 || ^13.0
illuminate/contracts
Version ^11.0 || ^12.0 || ^13.0

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform