Package Health

cjmellor/fal-ai-laravel

Usable with caveats: it has a clear license, strong release documentation, tests in the repository, and a steady release history. However, no commits or active maintainers were recorded in the last three months, and the repository has workflow-permission and security-policy gaps.

Latest v2.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target, which can require careful review because it runs with elevated event context; no untrusted checkout or script-injection findings were detected.

Lifecycle scriptscaution

The package uses post-autoload-dump and post-update-cmd scripts. These add install-time behavior that deserves review, although the signal does not establish that the scripts are unsafe.

Maintainerscaution

Only one registry account, Chris Mellor, has publish access. This is a real continuity risk for an individually owned project, despite the package's otherwise active release history.

Project backingcaution

The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so there is limited visible institutional backing.

Repo commit activitycaution

No commits and no active maintainers were recorded during the last three months, which conflicts with the recent release cadence and raises a maintenance-continuity concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Mellor

Direct Dependencies

DependencyLast ReleaseScore
saloonphp/saloon
Version ^3.0
hosmelq/sse-saloon
Version ^0.1.0
illuminate/support
Version ^12.0|^13.0

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform