Package Health

finller/laravel-insee-siren

The package has a clear README, changelog, repository tests, and an MIT license. Its release and commit activity has been inactive for over two years, while workflow permissions and unpinned actions add maintenance risk.

Latest v0.0.4PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The latest release was over two years ago, with no releases in the last 12 months. Four releases were published close together, but there is no evidence of continued release maintenance.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months, indicating little recent development activity despite the repository not being archived.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.

Version stabilitycaution

Version v0.0.4 is not a stable major release, so the package may still have compatibility risk for consumers. It is not marked as a prerelease, which partly offsets that concern.

Workflow auditcaution

All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a hygiene and maintenance concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Quentin Gabriele

Direct Dependencies

DependencyLast ReleaseScore
saloonphp/saloon
Version ^3.0
—
—
illuminate/contracts
Version ^10.0||^11.0
—
—
saloonphp/cache-plugin
Version ^3.0
—
—
saloonphp/laravel-plugin
Version ^3.5
—
—
saloonphp/rate-limit-plugin
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform