Package Health

jeffersongoncalves/website

The project has a large dependency surface and no published security policy. Its source is tested, actively changing, licensed, and has release notes, but the workflow audit found a high-confidence template-injection issue that deserves review.

Latest 13.33.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Dependency profilecaution

The release declares 49 runtime dependencies, including many framework and application integrations, which increases maintenance and transitive-dependency complexity.

Lifecycle scriptscaution

Four install or update lifecycle scripts can execute package-controlled commands during Composer operations, adding operational review burden. This is expected to some extent for a Laravel application but remains a supply-chain consideration.

Release historycaution

This is the package's first and only release, published less than one day ago, so there is no release history to establish long-term stability. Active repository commits partly compensate for the limited registry history.

Security policycaution

The repository has no security policy, leaving disclosure and response expectations undocumented.

Workflow auditcaution

All five workflows were analyzed and all 15 action references are pinned, with no untrusted checkout or script-injection trigger found. However, the high-confidence template-injection finding in update-changelog.yml and one workflow with top-level write permissions are meaningful workflow hygiene risks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
laravel/mcp
Version ^0.9.5
—
—
geoip2/geoip2
Version ^3.4
—
—
laravel/tinker
Version ^3.0
—
—
livewire/blaze
Version ^1.0
—
—
laravel/horizon
Version ^5.50
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform