Package Health

dashworthy/visualizations

The project is only 92 days old and still below 1.0, but it has released seven times and remains actively developed. Its small, concentrated contributor base and workflow hygiene leave meaningful maintenance and build-integrity caveats.

Latest 0.5.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install script runs during Composer installation. This is a supply-chain and installation-behavior consideration, though the signal does not show that the script is unsafe.

Repo bus factorcaution

Two contributors were active, but one made 87.5% of the recent commits. The organization-owned project provides some handoff capacity, partially offsetting this concentration.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but does not by itself indicate poor health.

Security policycaution

No repository security policy was found. This is a transparency gap for a package handling application data and permissions, though it is not evidence of an active defect.

Version stabilitycaution

Version 0.5.0 is not a stable major release, so APIs may still change; it is nevertheless not marked as a prerelease and recent releases contain no prerelease versions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrew Leach

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0||^12.0||^13.0
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
1 month ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform