Package Health

jackmartin/laravel-websockets

The release has useful documentation, repository tests, a clear MIT license, and no install-time scripts. Its workflow uses unpinned actions and has a low-confidence cache warning, while repository security scanning and a security policy are absent.

Latest v2.0.3PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has 64 releases, but its latest release was on November 30, 2021, with no releases in the last 12 months. That long publishing gap is a major abandonment concern.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the package's prolonged release inactivity.

Repo popularitycaution

The linked repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal to offset the inactivity.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than proof of unsafe code.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a package that handles WebSocket infrastructure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcel Pociot
Freek Van der Herten
Alex Renoki

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ^2.9
—
—
react/promise
Version ^2.0
—
—
guzzlehttp/psr7
Version ^1.5|^2.0
—
—
illuminate/http
Version ^6.3|^7.0|^8.0
—
—
clue/redis-react
Version ^2.3
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform