Package Health

hardimpactdev/craft-laravel

Unfit to use despite recent releases and solid packaging. The registry marks the package as abandoned, and the linked repository does not identify or mention this package; maintenance is also controlled by one contributor.

Latest v0.3.9PackagistPackagist

22%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no distinct replacement identified. Although the release history is active, package-level deprecation makes this release unsuitable for a new dependency.

Dangerous workflowscaution

One workflow uses pull_request_target and another uses workflow_run, both requiring careful trust-boundary handling. No untrusted checkout or script-injection patterns were detected, so the workflow risk is limited rather than severe.

Repo bus factorcaution

One contributor made all 16 commits in the last 3 months, leaving no demonstrated backup maintainer. This increases continuity risk for a user-owned project.

Repo package mentioncaution

The repository name does not match the package name, and its README does not mention the package. That raises a concrete concern that the published package may be associated with the wrong or repurposed repository.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this does not independently make the package unsafe, but it provides no additional evidence of community adoption.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

nckrtl

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^12.0 || ^13.0
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
1 month ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform