Package Health

cleaniquecoders/flowstone

The project has clear documentation, an MIT license, release notes, and organization backing. Its small audience and missing security policy leave less independent assurance.

Latest 1.5.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump lifecycle script runs during installation; this is common Composer behavior but adds execution during dependency installation.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, a meaningful sign that development activity has recently stalled despite the release history.

Repo popularitycaution

Five stars and two forks indicate a small user and contributor footprint, which provides limited external validation but is not by itself evidence of poor quality.

Security policycaution

No repository security policy was found, reducing transparency about how vulnerabilities are reported and handled.

Workflow auditcaution

All 15 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The cache-poisoning finding is low confidence and is treated as hygiene rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nasrul Hazim Bin Mohamad

Direct Dependencies

DependencyLast ReleaseScore
symfony/workflow
Version ^6.4||^7.0
—
—
livewire/livewire
Version ^3.0 || ^4.0
—
—
illuminate/contracts
Version ^10.0||^11.0||^12.0||^13.0
—
—
cleaniquecoders/traitify
Version ^1.2.1
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform