Package Health

laravel-lang/status-generator

It has a long, steady release history and an organization-owned repository. GitHub workflows use broad top-level write permissions and all eight actions are unpinned, while recent commits come from one contributor.

Latest 2.16.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Dependency profilecaution

The package declares 15 runtime dependencies, including translation clients and Laravel/Symfony components; this is a substantial dependency surface for a command-line tool and modestly increases maintenance exposure.

Repo bus factorcaution

All recent commits came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but no second active contributor is shown.

Repo commit activitycaution

The repository had 2 commits in the last 3 months, showing some recent activity but a relatively light maintenance pace.

Workflow auditcaution

All six workflows were analyzed with no reported audit findings or unsafe untrusted triggers. However, all 8 action references are unpinned and 4 workflows grant top-level write permissions, leaving avoidable reproducibility and token-scope weaknesses.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrey Helldar
Laravel-Lang Team

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^6.0 || ^7.0 || ^8.0
—
—
archtechx/enums
Version ^0.3.2 || ^1.0
—
—
phpunit/phpunit
Version ^10.0 || ^11.0 || ^12.0
—
—
symfony/console
Version ^6.0 || ^7.0 || ^8.0
—
—
guzzlehttp/guzzle
Version ^7.4
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform