Package Health

macramejs/macrame-laravel

The package has a small dependency surface, repository tests, and matching project ownership. Its workflow references are unpinned and the repository has no security policy, so pinning this version warrants extra care.

Latest v0.3.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

71

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was in December 2022, nearly four years before collection, and there were no releases in the last 12 months. Eight releases show some history, but the current cadence indicates meaningful maintenance risk.

Repo commit activitycaution

There were no commits and no active maintainers in the three months before collection. The later repository push date is compensating context, but recent activity remains weak.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are present. The build setup is appropriate, while the missing scanning is a modest hygiene gap.

Security policycaution

The repository has no security policy. This limits disclosure transparency, though it is a hygiene concern rather than evidence that the package is unsafe.

Version stabilitycaution

v0.3.0 is not a prerelease, but it remains below the 1.0 major line and half of recent versions were prereleases. This lowers maturity confidence without making the release unfit on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Lennart Carstens-Behrens

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^9.0
—
—
illuminate/contracts
Version ^9.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform