Package Health

elegantly/laravel-money

Use Brick/Money in your Laravel app

Latest v4.2.2PackagistPackagist

76%

Total Score

healthy

Healthy, with concentrated maintenance and workflow hygiene concerns.

Health Score Breakdown

Lifecycle scriptscaution

The package defines a post-autoload-dump install-time script. This is a potentially sensitive execution point, but a single script is not by itself evidence of poor package health.

Repo bus factorcaution

One contributor made 100% of the six commits in the last three months. Organization backing provides some handoff capacity, but the observed contributor base remains concentrated.

Repo commit activitycaution

The repository recorded six commits in the last three months, showing recent activity. However, all six came from one active maintainer, limiting independent maintenance capacity.

Security policycaution

The repository has no security policy. For a library handling monetary values, this is a modest transparency gap, though active releases and dependency scanning partly compensate.

Workflow auditcaution

All four workflows were analyzed, but all eight action references are unpinned, and one workflow has top-level write permissions. The high-confidence bot-conditions finding in the Dependabot auto-merge workflow adds a workflow hygiene concern; there is no untrusted checkout or script injection.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Quentin Gabriele

Direct Dependencies

DependencyLast ReleaseScore
brick/money
Version ^0.13.0||^0.14.0||^0.15.0
—
—
illuminate/contracts
Version ^13.0
—
—
spatie/laravel-package-tools
Version ^1.13.0
—
—

Weekly Downloads

Info

Last Published
9 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform