Package Health

jooservices/laravel-activities

This release appears suitable to depend on, with strong repository and package hygiene: it is a stable, non-deprecated release backed by an active, non-archived repository, tests, changelog, documentation, security policy, CI tooling, and clean workflow-risk checks. The main reservations are that the project is young at 72 days, all 11 recent commits came from one contributor, one CI workflow lacks top-level permissions, and the package uses post-install and post-update scripts. Organization ownership and recent merged pull requests provide some mitigation, but the limited operating history and concentrated maintenance base warrant continued monitoring before relying on it for highly critical functionality.

Latest v4.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-install and post-update Composer scripts, which increase installation-time execution exposure and deserve review, although their presence alone does not establish unsafe behavior.

Release historycaution

The package has five releases over 72 days with a median interval of about 15 days, indicating active early development but limited historical maturity.

Repo bus factorcaution

All 11 recent commits came from one contributor, creating a clear bus-factor risk; organization ownership partially mitigates handoff concerns but does not demonstrate a second active maintainer.

Repo commit activitycaution

The repository recorded 11 commits in the last three months, showing recent activity, but only one maintainer was active during that period, limiting evidence of sustained maintenance capacity.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity is not decisive and the package has stronger activity and hygiene signals.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Viet Vu

Direct Dependencies

DependencyLast ReleaseScore
jooservices/dto
Version ^3.2
—
—
laravel/framework
Version ^12.0|^13.0
—
—
jooservices/exceptions
Version ^4.0
—
—
mongodb/laravel-mongodb
Version ^5.10
—
—
jooservices/laravel-repository
Version ^4.0
—
—

Weekly Downloads

Info

Last Published
23 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform