Package Health

eslamddd/skeloton-package

The package includes tests, a changelog, and a matching MIT license, while dependency and security tooling are present. Its source has had no commits in over two years, and the workflow audit found a high-confidence bot-condition issue alongside broad permissions and unpinned actions.

Latest v3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

33

Health Score Breakdown

Release historydanger

The package has had 3 releases since December 2023 and none in the last 12 months; the latest release is nearly three years old, indicating likely abandonment.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months; combined with no registry releases in the last year, this is strong evidence of stalled maintenance.

Workflow auditdanger

All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-condition finding affects the Dependabot auto-merge workflow. No untrusted checkout or script injection was found, but the combined workflow hygiene is a real supply-chain concern.

Dependency profilecaution

Nine runtime dependencies, including Laravel, Livewire, Passport, and repository packages, create a relatively broad dependency surface for a package with limited recent release activity.

Lifecycle scriptscaution

The package runs a post-autoload-dump script during installation. This is a meaningful execution surface, but the signal provides no evidence that the script is unsafe or unusually broad.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Eslam

Direct Dependencies

DependencyLast ReleaseScore
laravel/ui
Version ^4.2
—
—
laravel/passport
Version ^11.3
—
—
livewire/livewire
Version ^2.10
—
—
illuminate/contracts
Version ^10.0
—
—
prettus/l5-repository
Version ^2.8
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform