Package Health

lemaur/markdown

This is a healthy, actively maintained release with a five-year history, nine releases in the last 12 months, a stable non-prerelease version, and no registry deprecation. The linked repository is active and unarchived, matches the package, contains tests and changelog material, uses Composer and Dependabot, and publishes a security policy. The main risks are a single active maintainer with all recent commits, very low repository popularity, an install-time post-autoload-dump script, and some GitHub Actions workflows with broad or unspecified token permissions; these warrant review but do not outweigh the strong release and repository maintenance evidence.

Latest 4.0.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health checks

Dangerous workflowscaution

Six workflows were analyzed; one uses pull_request_target, but there are no untrusted checkouts or script-injection findings. The isolated pull_request_target usage merits review but is not severe on the available evidence.

Lifecycle scriptscaution

The package declares a post-autoload-dump install lifecycle script. This adds installation complexity and should be reviewed before adoption, although the signal alone does not establish that the script is unsafe or damaging.

Maintainerscaution

Only one registry account, Maurizio, has publish access. This is a real publishing continuity concern, though the repository shows ongoing activity from the same maintainer.

Project backingcaution

The repository owner is an individual user rather than an organization. Combined with the single recent contributor, this provides less maintenance redundancy than organization-backed ownership.

Repo bus factorcaution

One contributor made all 4 commits in the last 3 months, giving a 100% top-contributor share. This creates a meaningful continuity and bus-factor concern for a user-owned project.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Maurizio

Direct Dependencies

DependencyLast ReleaseScore
league/commonmark
Version ^2.0
illuminate/contracts
Version ^11.0 || ^12.0 || ^13.0
spatie/laravel-package-tools
Version ^1.4.3

Weekly Downloads

Info

Last Published
10 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform