Package Health

moonshine/menu-manager

This release appears generally safe to depend on: it has a stable major version, a consistent release history with 7 releases in the last 12 months, an active and non-archived organization-owned repository, clear MIT licensing, and no install-time lifecycle scripts. The main concerns are limited recent repository activity (one commit in the last 3 months from one contributor), the absence of tests and a changelog, no security policy or security-scanning tooling, and very low repository popularity. These issues warrant monitoring, but the organization backing, recent release activity, matching repository, and small focused package structure keep the package in the healthy range.

Latest 4.18.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a supply-chain continuity concern, but this is partly offset by the organization-owned source repository and observed release activity.

Package scaffoldingcaution

A README is present and GitHub Releases are used, but neither the artifact nor the repository contains tests or a changelog. For a small readonly subtree split this is a real transparency and maintenance gap, although the release process provides some compensating evidence.

Repo bus factorcaution

All recent repository commits came from one contributor, creating concentration risk. Organization ownership provides some handoff capacity, but no second active contributor is shown in this signal.

Repo commit activitycaution

Only one commit was recorded in the last 3 months from one active maintainer, indicating thin recent development activity, though it is consistent with the package's recent release history.

Repo issue activitycaution

There were no new or closed issues and no pull requests in the last month; this is limited evidence of community activity, but the open-issue count is unknown and the repository is a readonly subtree split.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Danil Shutsky

Direct Dependencies

DependencyLast ReleaseScore
moonshine/ui
Version ^4.0
—
—
moonshine/core
Version ^4.0
—
—
moonshine/support
Version ^4.0
—
—
illuminate/support
Version ^10|^11|^12|^13
—
—
moonshine/contracts
Version ^4.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform