Package Health

daikazu/laratone

Healthy and suitable to depend on, with a current stable release, recent commits, regression tests, and clear release notes. The main caveats are a very small user base and incomplete repository security hygiene, including a missing security policy and permissive workflow settings.

Latest v5.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump lifecycle script during installation. This is an additional install-time execution surface, though the provided signal does not show dangerous behavior.

Repo popularitycaution

The repository has only 3 stars, 0 forks, and 1 watcher, so external adoption and independent visibility are limited. This is supporting evidence rather than a decisive problem for a small, actively maintained package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and assurance gap.

Security policycaution

The repository has no security policy, so users are not given a documented process for reporting vulnerabilities or receiving fixes.

Token permissionscaution

One workflow has no top-level permissions and another grants top-level write access, which is weaker workflow hardening than a consistently least-privileged configuration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mike Wall

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^12.0|^13.0
spatie/laravel-package-tools
Version ^1.19

Weekly Downloads

Info

Last Published
1 month ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform