Package Health

kanekescom/laravel-siasn-referensi

The repository has no commits in the last three months, and its workflows leave all 12 actions unpinned. It has a clear MIT license, release notes, and a matching repository, but workflow permissions and automation checks need care.

Latest v2.3.3PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install-time script runs during Composer installation. This adds execution surface and deserves review, although the signal does not show that the script is malicious or unusually risky.

Release historycaution

The package has 30 releases, but none in the last 12 months and the latest registry release was nearly two years ago, which raises maintenance and abandonment concerns.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the absence of recent registry releases and indicating limited current maintenance.

Security policycaution

The repository has no published security policy. This is a transparency and reporting gap, though it is a secondary concern for an otherwise identified and licensed project.

Workflow auditcaution

All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The high-confidence bot-condition finding also indicates a potentially spoofable actor check; no untrusted checkout or script-injection sink was found, so this is workflow hygiene risk rather than a severe standalone issue.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Achmad Hadi Kurnia

Direct Dependencies

DependencyLast ReleaseScore
league/csv
Version ^9.15
—
—
guzzlehttp/guzzle
Version ^7.2
—
—
illuminate/contracts
Version ^10.0|^11.0
—
—
spatie/laravel-fractal
Version ^6.0
—
—
kanekescom/laravel-helperia
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform