Package Health

ferdiunal/laravel-cache-couchdb

The package has a documented API, repository tests, a changelog, and a matching source project. Its workflow setup adds release-hygiene concerns through broad permissions, unpinned actions, and a high-confidence bot-condition finding.

Latest v0.1.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

25

Health Score Breakdown

Release historydanger

Only two releases were published, both around the first release in May 2023, with no releases in about three years. This is strong evidence of an inactive release line.

Repo commit activitydanger

There were zero commits and zero active maintainers in the past three months, consistent with the package having received no meaningful maintenance since 2023.

Workflow auditdanger

All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, limiting the severity.

Maintainerscaution

One registry maintainer is consistent with a user-owned project, but it provides little redundancy if that maintainer stops maintaining the package.

Project backingcaution

The registry namespace and repository are owned by the same individual, confirming a coherent user-backed project but not providing organizational maintenance capacity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ferdi ÜNAL

Direct Dependencies

DependencyLast ReleaseScore
doctrine/couchdb
Version ^1.0@beta
illuminate/contracts
Version ^9.0|^10.0
spatie/laravel-package-tools
Version ^1.14.0

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform