Package Health

laravel-myanmar-tools/font

Clear documentation, licensing, and a small dependency footprint make adoption easier. Maintenance has been quiet for nearly three years, while workflow checks show a high-confidence bot-condition issue and all action references are unpinned.

Latest v1.0.0PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

This is the sole release, published about 3 years and 8 months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the risk that maintenance has stalled.

Repo issue activitycaution

There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month, providing little evidence of active project response.

Security policycaution

The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is less serious for a small utility package than for security-sensitive software.

Workflow auditcaution

The audit found a high-confidence bot-conditions issue in the pull_request_target workflow, and all 9 analyzed action references are unpinned. The trigger has no untrusted checkout or script-injection sink, so these are workflow hygiene and supply-chain concerns rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pyae Sone Aung

Direct Dependencies

DependencyLast ReleaseScore
spatie/macroable
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform