Package Health

laravel-lang/json-fallback-hotfix

The source repository is organized and has tests, a license, release notes, and security tooling. However, recent commit activity is absent, releases are infrequent, and the registry marks this package abandoned.

Latest 2.3.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement beyond the same package name; this is a severe adoption concern despite the active-looking repository metadata.

Release historycaution

The package has 8 releases over about 4 years, with only 1 release in the last 12 months and a median interval of about 226 days; maintenance is present but slow.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, which weakens confidence in ongoing maintenance.

Repo package mentioncaution

The linked repository name does not match the package name, and its README does not mention this package, leaving uncertainty about whether the repository directly backs this release.

Workflow auditcaution

All 8 analyzed action references are unpinned and 4 of 6 workflows grant top-level write permissions. No untrusted triggers, injection sinks, or audit findings were reported, so this is a hygiene caution rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrey Helldar
Felipe Dsdev

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—
illuminate/translation
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform