Package Health

daltonmccleery/remote-models

It has clear documentation, repository tests, a matching source repository, and a permissive license. Maintenance has stalled for over 18 months, while both workflow actions are unpinned and no security policy is provided.

Latest 1.3.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers in the last three months, consistent with the repository having received no push for over 18 months. This materially raises abandonment risk.

Release historycaution

The package has 18 releases but none in the last 12 months, and its latest release was over 18 months ago. This is meaningful maintenance risk despite the earlier release history.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a real transparency gap for a package handling remote application data.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous sinks or audit findings, but both of its two action references are unpinned. That weakens build reproducibility and update safety without showing an active exploit path.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dalton McCleery

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.8
—
—
illuminate/support
Version ^11.0|^12.0
—
—
illuminate/database
Version ^11.0|^12.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform