Package Health

laravel-appkit/blameable

It has clear documentation, tests, an MIT license, security policy, and organization backing. Maintenance has stopped recently, and the automated workflows contain several high-confidence hygiene issues that warrant caution.

Latest v1.2.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Name lookalikedanger

The package borrows the identity of the much more established laravel/sail package, with an explicit lookalike identity signal; consumers could install the wrong package.

Workflow auditdanger

The audit completed all five workflows and found high-confidence template-injection issues, an unpinned container image, and spoofable bot conditions; all 11 action references are unpinned. The pull_request_target workflow had no untrusted checkout or script-injection sink, which limits the severity of that trigger itself.

Release historycaution

The package has only three releases and no releases in the last 12 months, with a median interval of about two years, indicating a sparse cadence.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months, a concrete sign that maintenance has stalled.

Repo issue activitycaution

There are no new or closed issues or pull requests in the last month, although two pull requests remain open, suggesting limited current project activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Darren Coutts

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^8.0|^9.0|^10.0|^11.0

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform