Package Health

inovector/mixpost

Clear licensing, documentation, tests, and release notes support adoption. The repository is active in other respects, but the recent three-month commit pause and weak workflow pinning reduce confidence in ongoing maintenance.

Latest 2.6.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. That recent pause is a meaningful maintenance concern, despite the broader release and repository evidence.

Repo issue activitycaution

The project still has some recent issue and pull-request activity, but only one issue was opened and one closed in the last month, with no pull requests merged. This provides limited evidence of ongoing maintenance.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. For a package with substantial application and dependency code, this is a modest transparency and hygiene gap.

Workflow auditcaution

All three workflows were analyzed and had no untrusted checkout or script-injection findings, but all 10 action references are unpinned and the test workflow uses high-confidence unpinned container images, including the floating latest tag. This weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dima Botezatu

Direct Dependencies

DependencyLast ReleaseScore
laravel/horizon
Version ^5.0
tightenco/ziggy
Version ^2.5
guzzlehttp/guzzle
Version ^7.8
intervention/image
Version ^2.7
illuminate/contracts
Version ^10.47|^11.0|^12.0

Weekly Downloads

Info

Last Published
6 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform