Package Health

heiner/agent-graph

Usable with caveats: it is actively maintained and well documented, but remains pre-v1 and all recent work comes from one contributor. The lack of repository security scanning and concentrated ownership add meaningful adoption risk.

Latest v0.18.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The package and repository are both owned by the same individual user, and no organization backing is shown. This is consistent and transparent, but it provides less maintenance redundancy than organization ownership.

Repo bus factorcaution

One contributor made all 25 commits in the last three months, creating a clear single-maintainer continuity risk. The repository is user-owned rather than organization-owned, so there is no provided project-backing evidence to compensate for that concentration.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is no demonstrated external adoption or review base. For a package only 110 days old this is a cautionary maturity signal, not a severe risk by itself.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The repository's security policy and clean workflow analysis provide some compensation, but security automation remains a hygiene gap.

Token permissionscaution

One of two workflows lacks top-level token permissions, while the other declares read-only permissions and none declares top-level write access. This is a minor permissions-hygiene gap rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Heiner Giehl

Direct Dependencies

DependencyLast ReleaseScore
laravel/ai
Version ^0.11.2
—
—
illuminate/cache
Version ^12.0 || ^13.0
—
—
illuminate/queue
Version ^12.0 || ^13.0
—
—
illuminate/events
Version ^12.0 || ^13.0
—
—
illuminate/console
Version ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform