Package Health

grazulex/laravel-flowpipe

Usable with caveats: the package is licensed, documented, tested, non-deprecated, and backed by a matching active repository. However, releases are infrequent and the repository had no commits from maintainers in the last three months, while security-policy coverage is limited.

Latest v1.3.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package has only three releases over 423 days, with a median interval of about 212 days; this indicates a slow release cadence, although a release was published recently.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, despite the recent repository push and current release.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and review gap.

Security policycaution

The repository has no security policy, so users have no documented project-specific process for reporting vulnerabilities or receiving security guidance.

Token permissionscaution

Two workflows declare read-only permissions, but the release workflow has top-level write permissions. This is broader automation access than necessary unless the release process requires it.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jean-Marc Strauven

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^7.3|^8.0
nesbot/carbon
Version ^3.10
illuminate/support
Version ^12.19|^13.0
illuminate/contracts
Version ^12.0|^13.0

Weekly Downloads

Info

Last Published
6 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform