Package Health

ddfsn/blade-components

This is a generally healthy and actively maintained release. It has 27 releases over 574 days, including 20 in the last 12 months with a median interval of about 4.8 days, is a stable non-prerelease version, is not deprecated, and is backed by a matching organization-owned repository that was pushed very recently. The package is licensed, well-scaffolded, documented, and uses no install-time lifecycle scripts. The main adoption risks are concentrated maintenance: all 63 commits in the last 3 months came from one contributor, with no repository tests or security scanning, no security policy, and incomplete explicit workflow token permissions. These are meaningful resilience and hygiene gaps, but do not outweigh the strong release and repository activity.

Latest 1.6.3PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact and repository include a README and changelog, and the README documents how to run tests and report security issues. Neither the artifact nor repository contains tests, which is a modest verification gap for a UI component library.

Repo bus factorcaution

All 63 recent commits came from one contributor, giving a complete concentration of commit activity and creating a meaningful continuity risk. Organization ownership provides some handoff potential, but no second active contributor is shown.

Repo issue activitycaution

There were two new issues and one new pull request in the last month, but none were closed or merged. This indicates some engagement while leaving a small concern about issue-response effectiveness.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The build setup is established, while security-process automation remains a hygiene gap.

Token permissionscaution

Neither workflow declares top-level permissions, and no workflow is reported with read-only permissions. Although no top-level write permissions were detected, explicit least-privilege configuration is incomplete.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kevin Dierkx

Direct Dependencies

DependencyLast ReleaseScore
illuminate/routing
Version *
illuminate/support
Version *
symfony/http-kernel
Version ^6.2|^7.0|^8.0
blade-ui-kit/blade-heroicons
Version ^2.6

Weekly Downloads

Info

Last Published
20 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform