Package Health

katalam/laravel-openimmo

The source repository is active and well-scaffolded, with tests, release notes, and read-only workflow permissions. A single-contributor history, license mismatch, and unpinned actions add adoption risk.

Latest v2.0.0PackagistPackagist

20%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names innobrain/laravel-openimmo as a replacement, making this release a poor dependency choice despite other healthy repository signals.

Licensecaution

The artifact includes a license file, but it is detected as GPL-3.0 while the manifest declares MIT; that unresolved mismatch creates legal and adoption uncertainty.

Release historycaution

The package has had seven releases, but none in the last 12 months and its latest registry release was about 19 months ago, indicating a stalled release line.

Repo bus factorcaution

All seven commits in the last three months came from one contributor, leaving maintenance dependent on a single person; organization ownership provides some handoff capacity but does not remove the concentration risk.

Security policycaution

The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bruno Görß

Direct Dependencies

DependencyLast ReleaseScore
jms/serializer
Version ^2.1 || ^3.5
—
—
symfony/serializer
Version ^5.3 || ^6.0
—
—
doctrine/annotations
Version ^2.0
—
—
illuminate/contracts
Version ^10.0||^11.0
—
—
goetas-webservices/xsd2php
Version *
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform