Package Health

illuma-law/laravel-hybrid-search

The package includes repository tests, a substantial README, and a clear MIT license. Its five-month release and commit silence, plus CI's broad permissions, unpinned actions, and high-confidence bot-condition finding, warrant care before adoption.

Latest v1.0.7PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Health Score Breakdown

Release historycaution

The package has eight releases, but they were concentrated in roughly one week and there has been no release for about five months, suggesting an uncertain release cadence.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of slowed maintenance for a package released only about five months ago.

Workflow auditcaution

All 12 analyzed action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. There is no untrusted checkout or script injection, but the combination remains a CI supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

illuma-law

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^11.0||^12.0||^13.0
illuminate/database
Version ^11.0||^12.0||^13.0
illuminate/contracts
Version ^11.0||^12.0||^13.0
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
4 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform