Package Health

foodieneers/seo

This release is actively maintained and has strong supporting evidence: 25 releases in the last 12 months, a stable v2.2 release, recent repository pushes, repository tests and changelog coverage, Composer tooling, Dependabot, and organization ownership. However, Packagist explicitly marks the package as abandoned and identifies foodineers/seo as the replacement, which is a decisive dependency-risk signal even though the linked repository remains active. Maintenance is also concentrated in one contributor, while workflow permissions and security-policy hygiene have gaps. Developers should migrate to the replacement package rather than adopt this abandoned package.

Latest v2.2PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and names foodineers/seo as its replacement. This is a severe dependency and maintenance risk despite the repository's current activity.

Dangerous workflowscaution

One of four workflows uses pull_request_target, specifically the Dependabot auto-merge workflow. No untrusted checkout or script-injection findings were detected, so the workflow posture is a review concern rather than a severe finding.

Lifecycle scriptscaution

The package declares a post-autoload-dump lifecycle script. This is an install-time execution surface that warrants review, although the signal alone does not establish that the script is unsafe.

Repo bus factorcaution

All 9 commits in the last 3 months came from one contributor, producing a 100% top-contributor share. Organization ownership provides some handoff capacity, but the observed contributor concentration remains a maintenance-continuity concern.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency, though it is a hygiene gap rather than evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Paride Azzari

Direct Dependencies

DependencyLast ReleaseScore
spatie/schema-org
Version ^4.0
—
—
illuminate/contracts
Version ^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform