Package Health

jwcobb/laravel-google-product-categories

Usable with caveats: it is a small, clearly licensed package with tests, release notes, and a matching repository, but it has had only one registry release in about 1 year 10 months and no commits in the last 3 months. Workflow permissions and the absence of a security policy add operational concerns.

Latest v1.0.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkouts or script-injection patterns were detected, so the workflow concern is limited rather than severe.

Release historycaution

This is the only release, published about 1 year 10 months ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance and compatibility work.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months. Although the repository is not archived and has a later push recorded, recent development activity is still unproven.

Security policycaution

No security policy is present in the repository, leaving no documented process for reporting or handling vulnerabilities.

Token permissionscaution

Three workflows declare top-level write permissions, while two do not declare top-level permissions. Broad or implicit workflow permissions increase the repository's automation exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

J Cobb

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.0||^11.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform