Package Health

mattitjaab/laravel-cision-feed

Usable with caveats: the package is clearly identified, licensed, tested, and backed by a structured repository, but maintenance has slowed. There have been no releases in about 14 months and no commits or active maintainers in the last three months.

Latest v2.1PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merge, which warrants care because that workflow class can expose elevated repository context. No untrusted checkouts or script-injection patterns were detected, limiting the concern.

Release historycaution

The package has five releases since September 2022, but no release in the last 12 months and the latest release was about 14 months ago. That materially raises maintenance and abandonment concerns.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the absent registry releases over the last year, this is the main reason to treat the package cautiously.

Repo issue activitycaution

There are no open issues and four open pull requests, but none were opened or merged in the last month. The lack of issue backlog is positive, while the inactive pull requests suggest limited recent project movement.

Repo popularitycaution

The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, so this does not make the package unfit, but it provides little independent evidence of broad community support.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mattitja AB

Direct Dependencies

DependencyLast ReleaseScore
symfony/dom-crawler
Version 7.4.x-dev
—
—
illuminate/contracts
Version ^10.0 || ^11.0 || ^12.0
—
—
symfony/css-selector
Version 7.4.x-dev
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform