Package Health

greksazoo/mnb-exchange-laravel

The README, changelog, MIT license, and package layout give consumers useful documentation. It has no install-time scripts, but its workflow actions are all unpinned, creating a smaller reproducibility concern.

Latest 1.1.8PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed, leaving the project dependent on a thin individual maintainer base; the linked repository is also owned by a user account rather than an organization.

Release historycaution

The latest release was published in February 2023, with no releases in the following three years and seven months; this is a substantial maintenance concern for a Laravel integration.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.

Security policycaution

The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less severe for this small package than the lack of recent maintenance.

Workflow auditcaution

Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all five referenced actions are unpinned, which weakens build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Zoltan Greksa

Direct Dependencies

DependencyLast ReleaseScore
illuminate/cache
Version ^5.0|^6.0|^7.0|^8.0|^9.0|^10.0
—
—
illuminate/support
Version ^8.0|^9.0|^10.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform