Package Health

mindtwo/px-user-laravel

This is a healthy, actively maintained release with strong supporting evidence: the package has been published for nearly four years, has 124 releases including 20 in the last 12 months, is stable and not deprecated, and the linked organization-owned repository is active, correctly associated, documented, licensed, and backed by a substantial test suite. The main concerns are that all seven commits in the last three months came from one contributor, the repository has no security policy or security-scanning tooling, and the workflow does not declare top-level token permissions. These are meaningful transparency and resilience gaps, but they do not outweigh the recent release activity, active repository, and organizational backing.

Latest 4.1.9PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All seven recent commits came from one contributor, creating a real continuity risk. Organizational ownership provides some ability to hand off maintenance, but no second active contributor is shown.

Repo toolingcaution

The repository uses Composer and Just for build tooling, but reports no security-scanning tools. This is a modest supply-chain hygiene gap rather than a severe risk by itself.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency, though it is not evidence that the package is unmaintained.

Token permissionscaution

The only workflow lacks top-level token permissions, which is a permissions-hygiene gap. It declares no top-level write access, so the risk is limited rather than severe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

mindtwo GmbH

Direct Dependencies

DependencyLast ReleaseScore
laravel/scout
Version ^10.13
—
—
laravel/framework
Version ^12.0|^13.0
—
—
mindtwo/two-tility
Version ^1.0
—
—
spatie/laravel-data
Version ^4.18
—
—
mindtwo/laravel-decorator
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform