Package Health

kafka-bus/laravel-bridge

kafka-bus/laravel-bridge v1.5.0 shows active registry release cadence (9 releases in the last 12 months; median ~4 days) and the source repository is not archived with recent pushes and merges, suggesting ongoing maintenance. However, maintenance is concentrated in a single active contributor (repo_bus_factor and repo_commit_activity both indicate full concentration), and the repo lacks a published security policy. Additionally, the packaged artifact signal indicates no bundled tests (even though the source repo has tests), which slightly increases adoption risk around CI parity. Overall this is usable, but you should weigh the single-maintainer/small-team risk and security-policy gap before depending on it broadly.

Latest v1.5.0PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Lifecycle scriptscaution

An install-time lifecycle script is present (post-autoload-dump), which is usually limited in scope, but it still means extra code may execute during Composer operations.

Maintainerscaution

The registry lists only 1 maintainer, matching the single-contributor development signal and reinforcing a thin maintenance coverage story.

Package scaffoldingcaution

The artifact includes README and CHANGELOG, and the repo has tests (repo_has_tests true), but the artifact-level signal indicates has_tests=false, suggesting tests may not be included in the published distribution.

Repo bus factorcaution

All recent commits appear to come from a single contributor (top_contributor_commit_share=1.0; contributor_count_3_months=1), which increases bus-factor risk if that person becomes unavailable.

Repo popularitycaution

Repository popularity counters are currently 0 for stars/forks/watchers, which is not a direct health failure but provides limited community adoption evidence for faster external auditing.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Kirill Popkov

Direct Dependencies

DependencyLast ReleaseScore
kafka-bus/core
Version ^1.3
—
—
kafka-bus/commiter
Version ^1.2
—
—
kafka-bus/messages
Version ^1.0
—
—
illuminate/contracts
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform