Package Health

creode/laravel-nova-assets

The MIT license, complete README, release notes, tests in the repository, and organization backing provide useful transparency. Maintenance has slowed, while workflow permissions, unpinned actions, and a high-confidence bot-condition warning add adoption risk.

Latest 2.8.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 31 releases but none in the last 12 months; its latest release was about 18 months ago. Earlier release history shows maturity, but the recent pause raises maintenance risk.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. This is a meaningful sign of currently limited maintenance capacity.

Security policycaution

The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, though Dependabot provides some compensating security tooling.

Workflow auditcaution

All 4 analyzed action references are unpinned, both workflows grant top-level write access, and a high-confidence bot-conditions finding warns that actor context may be spoofable. The pull_request_target workflow has no untrusted checkout or script-injection findings, so this is a hygiene and workflow-integrity concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Creode

Direct Dependencies

DependencyLast ReleaseScore
laravel/nova
Version ^4.27
—
—
intervention/image
Version ^3.0
—
—
illuminate/contracts
Version ^10.0 | ^11.0
—
—
creode/laravel-assets
Version ^1.4 | ^2.0
—
—
creode/permissions-seeder
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform