Package Health

glhd/linearavel

Recent releases and active work from two contributors provide a solid maintenance base. The MIT license, repository tests, and release notes improve transparency, but workflow controls and security documentation remain weaker than ideal.

Latest 0.1.4PackagistPackagist

73%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install-time script runs during Composer installation, adding execution-surface risk even though the signal does not show malicious behavior or what the script does.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.

Version stabilitycaution

Version 0.1.4 is not a stable-major release, so its API may still change; however, it is not a prerelease and recent releases have not been labeled prerelease.

Workflow auditcaution

All four workflows were analyzed, but all 12 action references are unpinned and one workflow has a high-confidence template-injection finding; the finding is a workflow hygiene concern because no untrusted checkout or script-injection sink was detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Morrell

Direct Dependencies

DependencyLast ReleaseScore
nikic/php-parser
Version ^5.0
saloonphp/saloon
Version ^4.0
guzzlehttp/guzzle
Version ^7.8|^8.0
illuminate/support
Version ^11.0|^12.0|^13.0
spatie/laravel-data
Version ^4.11

Weekly Downloads

Info

Last Published
1 hour ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform