Package Health

honed/bind

The repository is backed by an organization, includes tests, and has Dependabot scanning. A single registry maintainer, absent security policy, and workflow hygiene issues increase ownership and operational risk.

Latest v0.3.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This is a supply-chain surface that deserves caution because the signal provides no further detail about what the script executes.

Maintainerscaution

Only one registry publishing account is listed, which is a thin release-maintainer base. The organization-owned repository partly compensates for this limitation.

Release historycaution

The package is 462 days old but has only three releases, with one release in the last 12 months and a median interval of about 231 days. This indicates a slow release cadence.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months. Although a release was published recently, the lack of recent commit activity weakens evidence of ongoing maintenance.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external maturity signal for this young package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joshua Wallace

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^12.0||^13.0
—
—
illuminate/contracts
Version ^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform