Package Health

jeffersongoncalves/laravel-zero-self-update

This is a healthy, actively maintained early-stage package with a stable v1.1.0 release, a matching repository, clear documentation, an MIT license, repository tests, security policy, Dependabot, and recent activity from two contributors. Its main limitations are its short 76-day history, only three releases, very small adoption footprint, and incomplete explicit GitHub Actions token permissions; these warrant routine review but do not currently make the package unfit to depend on.

Latest v1.1.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publishing access, which limits publishing redundancy; however, repository activity shows a second active contributor, partially mitigating the operational concern.

Project backingcaution

The repository is owned by an individual account rather than an organization, so maintenance depends more directly on the identified contributors; current two-contributor activity provides some resilience.

Release historycaution

The package is only 76 days old with three releases and a median release interval of about 38 days, so its maintenance track record is still limited despite regular releases.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher, indicating minimal public adoption; this is supporting caution rather than a decisive health problem for a small package.

Token permissionscaution

Two workflows omit top-level permissions and one declares top-level write access, leaving GitHub Actions privilege boundaries less explicit than ideal even though no dangerous workflow pattern was detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jefferson Goncalves

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.10
—
—
illuminate/console
Version ^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform