Package Health

mtolhuys/laravel-schematics

Unfit to use for a new dependency: the repository is archived and the last release was about six years ago. Despite a clear license, substantial documentation, tests in the repository, and a matching source project, maintenance and security support are no longer dependable.

Latest 0.10.3PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

60

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Release historydanger

The package has 43 releases but none in the last 12 months; its latest release was on March 21, 2020, about six years and six months before collection. This long release gap strongly indicates that current maintenance cannot be relied on.

Repository archiveddanger

The linked repository is explicitly archived, which is a severe abandonment risk for a package that provides application functionality and may need compatibility fixes. The recorded push date does not offset the repository's archived status.

Repo bus factorcaution

All recent commits came from one contributor, giving the project a complete single-person commit concentration. With a user-owned project rather than organization backing, there is no shown handoff capacity to reduce this risk.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, with one active maintainer, providing little evidence of ongoing development or support. This is consistent with the archived repository and does not compensate for the stale release history.

Security policycaution

The repository has no security policy, so users have no documented process for reporting or handling vulnerabilities. This is an additional transparency gap, especially concerning for an archived package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Maarten Tolhuijs

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform