Package Health

hpwebdeveloper/laravel-env-settings

This is a well-documented, actively developed Laravel package with a permissive MIT license, extensive tests, a substantial repository file tree, CI and security tooling, and no deprecation or archival indicators. However, it is very young at 17 days, has released 12 versions in that period, and all recent commits come from one contributor; the single-maintainer bus factor, install-time lifecycle scripts, absent security policy, and several workflows with top-level write permissions create meaningful adoption and operational risks. Overall it appears usable for a dependency, but its long-term maturity and maintenance resilience are not yet established.

Latest v1.7.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-install-cmd and post-update-cmd scripts, which expand installation-time execution and warrant review before adoption even though no maliciousness conclusion is drawn here.

Maintainerscaution

Only one registry maintainer is listed. This is not itself evidence of poor ownership, but it provides little publishing redundancy for a young package.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no provided organizational backing to compensate for the concentrated maintainer activity.

Release historycaution

The package is only 17 days old but has 12 releases, including 11 in the last 12 months and a median interval of about 16 hours; this shows strong activity but limited time to establish maturity and release stability.

Repo bus factorcaution

All 25 recent commits came from one contributor, giving the project a single-person bus factor and increasing abandonment or continuity risk if that contributor becomes unavailable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hamed Panjeh

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
29 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform