Package Health

heyosseus/filum

Filum v1.0.0 presents a generally healthy but very young dependency profile. It is licensed, non-deprecated, actively published, backed by a matching repository with documentation, changelog, repository tests, security policy, Dependabot, and restrictive workflow permissions. The main concerns are only 39 days of project history, rapid early releases, a single active contributor with all recent commits, and modest repository adoption, which increase maturity and continuity risk. It is reasonable to evaluate for use, but production adopters should monitor maintenance and future releases because the project has not yet demonstrated long-term stability or maintainer redundancy.

Latest v1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health checks

Maintainerscaution

Only one registry account has publish access. This is a continuity concern for a user-owned project because release operations depend on a single publisher, although repository activity provides evidence that the project is currently being maintained.

Project backingcaution

The source repository is owned by a user account rather than an organization, so there is no organizational maintenance backing to offset the single-contributor profile.

Release historycaution

Eight releases in 39 days show active development, but the short history and median release interval of about 4 hours indicate limited evidence of long-term maturity and potentially rapid iteration.

Repo bus factorcaution

All three recent commits came from one contributor, creating a clear bus-factor and continuity risk; the repository is user-owned rather than organization-owned, so there is no project-backing evidence to compensate for this concentration.

Repo commit activitycaution

Three commits were made in the last three months and the repository was recently updated, showing current activity, but the low volume limits evidence of sustained maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

heyosseus

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.11.5 || ^5.6.5
illuminate/console
Version ^12.0 || ^13.0
illuminate/support
Version ^12.0 || ^13.0
illuminate/database
Version ^12.0 || ^13.0
illuminate/contracts
Version ^12.0 || ^13.0

Weekly Downloads

Info

Last Published
10 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform