Package Health

grantholle/scru128-laravel

Usable with caveats: this is a well-scaffolded, clearly matched Laravel package, but it is less than three hours old and has no demonstrated maintenance history yet. Review its install script and GitHub workflow permissions before adopting it broadly.

Latest 1.0.1PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One of five workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkouts or script-injection patterns were detected, so the workflow setup presents limited but real review risk.

Lifecycle scriptscaution

A post-autoload-dump install-time script is present. This is a meaningful execution point for consumers and warrants review, though the signal alone does not establish that the script is unsafe.

Maintainerscaution

One registry publishing account creates a limited bus for releases, but the linked repository is owned by the same individual and the package is not organization-backed, so this remains a modest resilience concern.

Project backingcaution

The registry namespace and repository owner match, but both identify an individual rather than an organization, so the package has limited visible institutional backing.

Release historycaution

The package is less than three hours old and has only two releases, so there is not yet enough history to demonstrate sustained maintenance or release discipline.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Grant Holle

Direct Dependencies

DependencyLast ReleaseScore
grantholle/scru128
Version ^1.0
illuminate/database
Version ^11.0||^12.0||^13.0

Weekly Downloads

Info

Last Published
1 day ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform