Package Health

connora/laravel-primevue-starter-kit

This release appears healthy and suitable to depend on: it is actively and frequently released, uses a stable non-prerelease version, is not deprecated, has a matching non-archived source repository, includes MIT licensing, tests, substantial package contents, and recent repository activity. The main concerns are that all recent commits come from one contributor, the package defines several install-time lifecycle scripts whose behavior is not shown here, and the repository lacks an explicit security policy and top-level GitHub Actions token permissions. These are meaningful transparency and continuity gaps, but they do not outweigh the strong release and repository evidence.

Latest v4.2.5PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Lifecycle scriptscaution

Four install/update lifecycle scripts are present: post-autoload-dump, post-create-project-cmd, post-root-package-install, and post-update-cmd. Their presence is relevant supply-chain and reproducibility risk, although this signal does not show that the scripts are unsafe.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the concentrated maintainer activity represents a real single-owner continuity risk.

Repo bus factorcaution

One contributor made all seven commits in the last 3 months, creating a genuine continuity and abandonment risk for a user-owned project.

Repo commit activitycaution

Seven commits were made in the last 3 months, showing recent activity, but they came from only one active maintainer.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
laravel/fortify
Version ^1.36
—
—
laravel/framework
Version ^13.15
—
—
spatie/laravel-data
Version ^4.14
—
—
inertiajs/inertia-laravel
Version ^3.0
—
—
spatie/laravel-typescript-transformer
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform