Package Health

innoboxrr/search-surge

This is a generally usable and reasonably mature release: it has existed for about 3 years 7 months, has 16 releases including 4 in the last 12 months, uses a stable non-prerelease version, is not deprecated or archived, and has a matching repository with substantial test coverage and CI tooling visible in the source tree. The main concern is that repository activity reports no commits and no active maintainers in the last 3 months, despite the latest release being published recently, which weakens evidence of ongoing hands-on maintenance. Security transparency is also limited by the lack of a security policy and security scanning, while workflow permission and untrusted-checkout findings warrant review, but these do not by themselves make the package unfit to depend on.

Latest 3.0.3PackagistPackagist

74%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

Two workflows were analyzed and none use pull_request_target or script injection, but one workflow uses an untrusted checkout pattern, so its automation should be reviewed before treating the CI setup as fully hardened.

Maintainerscaution

Only one registry account has publish access, which is a modest publishing continuity concern, although the repository is owned by an organization and the release history shows continued publishing.

Repo commit activitycaution

The repository reports 0 commits and 0 active maintainers in the last 3 months, which is the clearest maintenance concern and conflicts with the recent registry release and recent repository push.

Repo issue activitycaution

There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral to mildly limited evidence because the absence of backlog does not establish active maintenance.

Repo popularitycaution

The repository has zero stars and forks and one watcher. This provides little external validation, but popularity is supporting evidence rather than a health verdict for a package with other maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Homero Raul

Direct Dependencies

DependencyLast ReleaseScore
illuminate/console
Version ^12.0|^13.0
illuminate/support
Version ^12.0|^13.0
illuminate/database
Version ^12.0|^13.0
illuminate/contracts
Version ^12.0|^13.0

Weekly Downloads

Info

Last Published
16 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform