Package Health

fourdotsix/tenancy-mapping

The repository has had no commits in the last three months, and its only release is about ten months old. Automated workflows also use unpinned actions and contain a high-confidence bot-condition warning, despite having tests, documentation, and Dependabot.

Latest 1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, a concrete sign that maintenance has slowed for a young package.

Workflow auditdanger

All 12 action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. There are no untrusted checkouts or script injections, but the workflow setup still needs hardening.

Lifecycle scriptscaution

The package uses a post-autoload-dump install-time script. This is worth awareness during installation, but the signal alone does not show an unsafe or excessive lifecycle action.

Release historycaution

This is a young package with one release, first published about ten months ago, so there is little release history to establish long-term maintenance.

Repo issue activitycaution

There are no new issues or merged pull requests in the last month, although two pull requests remain open; this provides limited evidence of active maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hash

Direct Dependencies

DependencyLast ReleaseScore
dallgoot/yaml
Version ^1.0
stancl/tenancy
Version dev-master
illuminate/contracts
Version ^11.0||^12.0
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
10 months ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform