Package Health

hotwired-laravel/turbo-laravel

Documentation, licensing, release notes, and repository ownership provide a solid maintenance foundation. Recent repository activity is quiet, and one workflow grants broader write access than necessary, so ongoing care should be watched.

Latest 2.6.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package defines a post-autoload-dump install-time script, so dependency installation can execute package-provided behavior. This is a real supply-chain surface, but the signal does not show that the script is malicious or unusually risky.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating a current maintenance pause. The recent 2.6.0 release and May repository push provide some compensating evidence, so this is a caution rather than a severe abandonment signal.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, with only 2 open issues and no open pull requests. This reinforces the quiet recent development picture, although the low issue count is not itself a major concern.

Workflow auditcaution

Both workflows were analyzed successfully, all four action references are pinned, and no untrusted checkout, script injection, or audit findings were reported. One workflow has top-level write permissions, which is a mild hygiene concern without an untrusted trigger or sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tony Messias

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform