Package Health

jkudish/laravel-ai-pricing

Clear documentation, a matching repository, and an MIT license make adoption straightforward. Automated security tooling and two active contributors provide useful maintenance coverage, though install-time scripting and unpinned workflow actions warrant routine review.

Latest v0.2.1PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

The package declares a post-autoload-dump install-time script, which adds execution during Composer operations. No provided signal shows that this script is harmful, so this is a limited supply-chain hygiene concern.

Project backingcaution

The registry namespace and repository are owned by the same individual, so the package has clear ownership but no organizational backing indicated. The second active contributor partly offsets that limitation.

Version stabilitycaution

Version v0.2.1 is not a stable major release, so its API may still change. It is not marked as a prerelease, reducing the concern somewhat.

Workflow auditcaution

All three workflows were analyzed with no audit findings or untrusted checkouts. However, all eight action references are unpinned and one workflow grants top-level write access; these are hygiene concerns without a demonstrated dangerous sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Joey Kudish

Direct Dependencies

DependencyLast ReleaseScore
brick/math
Version ^0.14.2 || ^0.15 || ^0.16 || ^0.17 || ^0.18 || ^0.19 || ^0.20 || ^1.0
—
—
illuminate/http
Version ^12.0||^13.0
—
—
illuminate/cache
Version ^12.0||^13.0
—
—
illuminate/console
Version ^12.0||^13.0
—
—
illuminate/support
Version ^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform