Package Health

channlabs/starter-kit

Tests, a stable release, and an MIT license provide a sound starting point. However, the repository has had no commits for about eight months, and its workflows use five unpinned actions. The repository also does not name or document this package clearly.

Latest v1.0.2PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is about 241 days old with three releases, all published within roughly 18 hours in January; this shows an initial launch but little release history afterward.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, while the repository was last pushed about eight months ago; this is meaningful evidence of stalled maintenance.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the package-to-source relationship is not clearly documented.

Security policycaution

The repository has no security policy, which weakens vulnerability-reporting transparency for a web application starter kit.

Workflow auditcaution

Both workflows were analyzed successfully with no dangerous audit findings, but all five referenced actions are unpinned and one workflow grants top-level write permissions, leaving avoidable supply-chain and token-scope exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
laravel/tinker
Version ^2.10.1
laravel/fortify
Version ^1.30
laravel/framework
Version ^12.0
laravel/wayfinder
Version ^0.1.9
inertiajs/inertia-laravel
Version ^2.0

Weekly Downloads

Info

Last Published
8 months ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform