Package Health

foxws/laravel-modelcache

Healthy and reasonable to depend on. It has a current stable release, active repository work, tests, documentation, release notes, and balanced recent contributors; the main caveats are a small project footprint and permissive GitHub Actions settings.

Latest 1.4.2PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target, which can be sensitive because it runs with elevated repository context. No untrusted checkouts or script-injection patterns were detected, limiting the concern.

Lifecycle scriptscaution

A post-autoload-dump install-time script is present, so installation performs extra package actions and deserves review, but this is a common Composer lifecycle hook and is not by itself a sign of abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.

Token permissionscaution

Three workflows declare top-level write permissions and two declare no top-level permissions, which is broader or less explicit than ideal for CI hardening. This is a repository hygiene concern rather than evidence that the package is unmaintained.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

francoism90

Direct Dependencies

DependencyLast ReleaseScore
illuminate/cache
Version ^12.0|^13.0
illuminate/console
Version ^12.0|^13.0
illuminate/support
Version ^12.0|^13.0
illuminate/contracts
Version ^12.0|^13.0
spatie/laravel-package-tools
Version ^1.9

Weekly Downloads

Info

Last Published
4 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform