Package Health

elazaroo/pulse-boosted

The package has a clear license, repository tests, a changelog, and a security policy. Install-time automation and absent security scanning leave additional operational risk.

Latest v1.0.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script, which adds execution and review risk beyond a package with no lifecycle automation.

Project backingcaution

The repository is owned by an individual rather than an organization, so continuity depends more directly on the maintainers; the recent multi-contributor activity partly offsets that concern.

Release historycaution

This is the first release, published one day ago, so there is no meaningful history showing sustained maintenance or compatibility over time.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest gap in ongoing project hygiene.

Workflow auditcaution

The workflow audit completed fully and found read-only permissions with all action references pinned, but it reported six high-confidence unpinned container-image findings in tests.yml. These are CI reproducibility and supply-chain hygiene concerns, not evidence that the release is malicious.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eneko Lazaro
Taylor Otwell

Direct Dependencies

DependencyLast ReleaseScore
league/uri
Version ^7.5.1
—
—
nesbot/carbon
Version ^2.67|^3.0
—
—
illuminate/auth
Version ^11.0.8|^12.0|^13.0
—
—
illuminate/http
Version ^11.0.8|^12.0|^13.0
—
—
illuminate/view
Version ^11.0.8|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform