Package Health

naowas/entrust

It includes repository tests, a stable release, a clear MIT license, and no install-time scripts. However, maintenance has stopped for more than three years, and the workflow leaves its action unpinned; pin this version only if you can accept limited ongoing support.

Latest 6.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The latest release was published in February 2023, with no releases in the following more than three years. This is a substantial maintenance concern for a Laravel integration package.

Repo commit activitycaution

The repository recorded no commits and no active maintainers during the last three months, consistent with the long release gap. The repository is not archived, but there is no recent activity showing ongoing maintenance.

Security policycaution

No security policy was found, reducing transparency for a package that handles role and permission checks. This is a documentation and response-process gap rather than evidence of a security flaw.

Workflow auditcaution

The sole workflow was analyzed successfully and has no dangerous triggers or audit findings, but its one action use is unpinned. That leaves the build exposed to changing action contents and is a modest supply-chain hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Zizaco Zizuini
Andrew Elkins
Ben Batschelet
Michele Angioni
Giorgi Ghughunishvili
Naowas Morshed Eimon

Direct Dependencies

DependencyLast ReleaseScore
illuminate/cache
Version ~6.0|^7.0|^8.0|^9.0|^10.0
—
—
illuminate/console
Version ~6.0|^7.0|^8.0|^9.0|^10.0
—
—
illuminate/support
Version ~6.0|^7.0|^8.0|^9.0|^10.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform