Package Health

chrisdicarlo/laravel-config-checker

Package to check that configuration key references actually exist in your config files.

Latest v1.4.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merging. No untrusted checkouts or script-injection patterns were detected, but this privileged workflow warrants caution because it operates in a sensitive pull-request context.

Lifecycle scriptscaution

The package runs a post-autoload-dump Composer lifecycle script. This is an avoidable installation-time execution surface, although the signal does not show that the script is malicious or unusually complex.

Maintainerscaution

Only one registry account has publish access. That is a modest resilience concern for a user-owned project, though repository activity and matching ownership provide some compensating context.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is the clearest maintenance concern, although the recent push and release history show the project has not been abandoned for years.

Repo issue activitycaution

There are no open issues and four open pull requests, but no issues or pull requests were newly created or merged in the last month, indicating limited current interaction.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Di Carlo

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.0||^11.0||^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform