Package Health

masterix21/laravel-bookings

Documentation is thorough, and the repository includes tests, release notes, and a security policy. Maintenance is concentrated in one contributor, while workflow permissions, unpinned actions, and a high-confidence bot-condition warning add operational risk.

Latest 2.0.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one account has registry publishing access. The repository is also user-owned rather than organization-owned, so there is no provided organizational backing to offset the concentrated maintainer base.

Project backingcaution

The package and repository share the same user owner, confirming the repository relationship, but the owner type is User rather than Organization and does not provide broader backing.

Repo bus factorcaution

One contributor made all 23 commits in the last three months, giving the project a single-maintainer bus factor and increasing continuity risk if that contributor becomes unavailable.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This is a hygiene gap, partially offset by the repository's separate security policy.

Workflow auditcaution

All five workflows were analyzed, but all 14 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a caution rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Luca Longo

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^3.8
—
—
spatie/period
Version ^2.4
—
—
illuminate/contracts
Version ^12.0 || ^13.0
—
—
spatie/laravel-package-tools
Version ^1.92
—
—
staudenmeir/belongs-to-through
Version ^2.16
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform