Package Health

laravelmcp/mcp

A single publisher and unpinned workflow actions reduce resilience and build reproducibility. The package is otherwise clearly documented, tested, licensed, and not archived.

Latest v1.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

One registry publishing account provides a thin publishing base, increasing continuity risk; the repository is user-owned rather than organization-backed, so there is no compensating organizational context here.

Release historycaution

The package has only two releases, with the latest about 18 months ago and none in the last 12 months; this indicates a real maintenance concern for a young integration library.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last 3 months, which weakens evidence of ongoing maintenance, although it is not archived.

Workflow auditcaution

All 3 analyzed action references are unpinned, reducing build reproducibility. The workflow has no untrusted checkout, injection, or high-confidence audit findings, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mohamed Abdelmenem

Direct Dependencies

DependencyLast ReleaseScore
react/http
Version ^1.9
—
—
react/socket
Version ^1.12
—
—
cboden/ratchet
Version ^0.4.4
—
—
guzzlehttp/guzzle
Version ^7.0
—
—
illuminate/support
Version ^10.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform