Package Health

inventas/momentum-lock

The source repository has tests and a clear README, and organization backing adds some continuity. Its four releases landed on one day, with no commits in the last three months, while CI dependencies are unpinned. Pin this version and confirm future Laravel support before adopting.

Latest v0.4.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is only 110 days old and has four releases, but all four were published on the same day with no later release activity, leaving ongoing maintenance unproven.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. For a package this young, that makes continued support uncertain rather than proving abandonment.

Repo toolingcaution

The project uses Composer build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk by itself.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unspecified. The package’s clear source and tests provide some compensating transparency, so this is a minor concern.

Version stabilitycaution

v0.4.0 is not marked as a prerelease, but the 0.x major version signals an API that may still change and warrants care for a dependency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Boris Lepikhin
Lennart Fischer

Direct Dependencies

DependencyLast ReleaseScore
illuminate/auth
Version ^12.0|^13.0
illuminate/support
Version ^12.0|^13.0
spatie/laravel-data
Version ^4.0
spatie/laravel-typescript-transformer
Version ^2.6

Weekly Downloads

Info

Last Published
3 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform