Package Health

fapost/support

This is a young but reasonably transparent and actively maintained package: it has three releases over 30 days, a current non-archived repository, two active contributors, organization backing, a matching README, a clear Apache-2.0 license, Composer dependency tooling, Dependabot, and a security policy. The main concerns are its early v0.x maturity, absence of tests and a changelog in both the artifact and repository, very limited repository adoption, and a GitHub Actions workflow with top-level write permissions and pull_request_target usage. It appears usable for adoption with normal caution around its immature API and limited validation history, rather than being an abandonment or registry-health risk.

Latest v0.2.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

The repository has one pull_request_target workflow. Although no untrusted checkout or script injection was detected, this workflow class warrants caution because it can operate with elevated repository context.

Package scaffoldingcaution

A substantial README documents the package’s purpose, requirements, namespace, and design rules, but tests and a changelog are absent in both the artifact and repository; for reusable framework primitives, the missing tests are a genuine validation gap.

Release historycaution

Three releases in the first 30 days, with a median interval of about 15 days, show active initial publishing but provide only a short maintenance history.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this leaves little external adoption evidence for a package that is only 30 days old.

Token permissionscaution

The sole workflow declares top-level write permissions. This is broader than a least-privilege configuration and increases workflow compromise impact, despite the absence of other detected workflow hazards.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
fapost/foundation
Version ^0.2
illuminate/support
Version ^11.0 || ^12.0
illuminate/database
Version ^11.0 || ^12.0

Weekly Downloads

Info

Last Published
18 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform