Package Health

laravel/doctor

The package is clearly documented, licensed, and has release notes for this version. Its repository is actively developed with four recent contributors, though most commits come from one person and six of eight workflow actions are unpinned.

Latest v0.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

Only one release has been published, 53 days after the first release, so long-term maintenance and release continuity are not yet demonstrated.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected; the repository's separate security policy and workflow audit provide some compensating transparency.

Version stabilitycaution

Version v0.1.0 is not a stable major release, which signals an early API and maturity stage even though it is not marked as a prerelease.

Workflow auditcaution

All four workflows were analyzed with no auditor findings, no untrusted checkouts, and read-only permissions in three workflows. However, six of eight action references are unpinned and one workflow has top-level write permissions, leaving moderate reproducibility and token-scope hygiene gaps.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Taylor Otwell

Direct Dependencies

DependencyLast ReleaseScore
composer/semver
Version ^3.0
laravel/prompts
Version ^0.3.21
illuminate/console
Version ^12.0|^13.0
illuminate/process
Version ^12.0|^13.0
illuminate/support
Version ^12.0|^13.0

Weekly Downloads

Info

Last Published
2 months ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform