Package Health

byrcsc/laravel-checklist

Usable with caveats: the release is well-documented, licensed, actively built, and backed by a matching organization repository. It is only 39 days old, has one release and one active contributor, with an install script and a write-enabled automation workflow adding operational risk.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Dangerous workflowscaution

One of three workflows uses pull_request_target, a sensitive automation trigger. No untrusted checkout or script injection was detected, so this is a workflow-risk caution rather than a severe finding.

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This is an additional execution point during installation and deserves review, although the signal does not show that the script is malicious or unusually broad.

Release historycaution

This is a very new package, only 39 days old, with one release and no established release cadence. That leaves limited evidence of long-term maintenance and compatibility stability.

Repo bus factorcaution

All 16 recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is evidenced here.

Token permissionscaution

All workflows declare permissions, and two are read-only; one Dependabot auto-merge workflow has top-level write permissions, increasing the impact of an automation compromise.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ryan Catapang

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^12.0||^13.0
—
—
illuminate/events
Version ^12.0||^13.0
—
—
illuminate/console
Version ^12.0||^13.0
—
—
illuminate/support
Version ^12.0||^13.0
—
—
illuminate/database
Version ^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform