Package Health

mvanduijker/laravel-mercure-broadcaster

It includes a substantial README, repository tests, a changelog, and exact-version release notes. The small project has no security policy, and its workflow uses three unpinned actions.

Latest 3.9.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months. This is a meaningful maintenance concern, although the assessed release was published recently.

Repo issue activitycaution

There is limited recent issue activity, with one new issue and no closures in the last month. The small volume is not severe, but it provides little evidence of ongoing responsiveness.

Repo toolingcaution

The project uses Composer build tooling, but no security scanning tools were detected, leaving automated security hygiene weaker than it could be.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or write permissions. However, all 3 action references are unpinned, which is a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mark van Duijker

Direct Dependencies

DependencyLast ReleaseScore
lcobucci/jwt
Version ~4.0|~5.0
—
—
symfony/mercure
Version ~0.4
—
—
illuminate/broadcasting
Version ~6.0|~7.0|~8.0|~9.0|~10.0|~11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform