Package Health

deepdigs/laravel-vault-suite

The repository includes tests, documentation, and a clear license, which supports adoption. Workflow safeguards are weak, with unpinned actions and a high-confidence bot-condition finding; the project also has limited visible ownership capacity.

Latest v0.1.0-alpha.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, and the repository is user-owned rather than organization-backed. This leaves a thin visible publishing and maintenance base.

Release historycaution

The package is about 340 days old but has only two releases, both within the same release period, indicating limited release maturity and an uncertain maintenance pattern.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance concern for a package intended to manage application secrets.

Security policycaution

The repository has no SECURITY.md or other security policy. For a library that handles Vault and application secrets, this weakens vulnerability-reporting transparency.

Version stabilitycaution

The assessed version is v0.1.0-alpha.2, and all recent releases are prereleases. This signals an API and maintenance profile that may still change substantially.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Omar Karray

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^10.0|^11.0|^12.0
—
—
illuminate/support
Version ^10.0|^11.0|^12.0
—
—
illuminate/contracts
Version ^10.0|^11.0|^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
11 months ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform