Package Health

gabrielmoura/laravel-pennant-redis

Usable with caveats: the package is licensed, stable, clearly backed by its matching repository, and not deprecated or archived. However, it has had no release in about two years and no commits in the last three months, with only one maintainer and limited security documentation.

Latest 1.2PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historydanger

There have been three releases since November 2023, but none in the last two years and none during the last 12 months, indicating likely slowing or stopped maintenance.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the concern that maintenance has stalled.

Lifecycle scriptscaution

The package defines a post-autoload-dump lifecycle script; because the script's behavior is not shown, it adds some install-time review risk even though no dangerous workflow was detected.

Maintainerscaution

Only one registry account has publish access. That is a meaningful continuity risk for a user-owned project because release and maintenance capacity depends on a single person.

Project backingcaution

The registry namespace and repository owner match, but both identify an individual rather than an organization, so the project has clear ownership without organizational backing.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Gabriel Moura

Direct Dependencies

DependencyLast ReleaseScore
laravel/pennant
Version >=1.5
illuminate/redis
Version >=v10

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform