Package Health

fidum/laravel-schedule-queue-command

Clear documentation and release notes support adoption, while the repository remains active and backed by an organization. The single-contributor activity, slow release cadence, and workflow hygiene issues warrant pinning this version and monitoring future maintenance.

Latest 2.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. That is normal for a small organization-backed project, but it still leaves publishing dependent on one person.

Release historycaution

The package has existed for about four years, but it has only seven releases, one in the last 12 months, and a median release interval of about nine months. This indicates a slower maintenance cadence, though not abandonment by itself.

Repo bus factorcaution

All two recent commits came from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown in this period.

Security policycaution

No repository security policy was found, leaving the project's vulnerability-reporting process unclear.

Workflow auditcaution

All five workflows were analyzed without failures and no untrusted checkout or script-injection sinks were found. However, all 12 action references are unpinned, three workflows grant top-level write access, and a high-confidence bot-conditions finding remains, creating workflow supply-chain hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Mason

Direct Dependencies

DependencyLast ReleaseScore
illuminate/console
Version ^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform