Package Health

nativephp/laravel

The package is clearly documented, licensed, tested in its repository, and has a small runtime dependency set. Its maintenance signals are outweighed by the repository being archived and the registry marking the package abandoned; use NativePHP/desktop instead.

Latest 1.3.1PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package abandoned and names NativePHP/desktop as its replacement, making continued dependency adoption a severe lifecycle risk.

Repository archiveddanger

The linked NativePHP organization repository is archived, which strongly indicates the source is no longer intended for active maintenance despite a recent push timestamp.

Release historycaution

Although the package has 30 releases over about three years, it has had no releases in the last 12 months, indicating that release activity has stopped.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months, reinforcing the abandonment concern.

Workflow auditcaution

All five workflows were analyzed, but every one of 13 action references is unpinned and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow; these add supply-chain hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marcel Pociot
Simon Hamp

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^6.2|^7.0
—
—
illuminate/contracts
Version ^10.0|^11.0|^12.0
—
—
spatie/laravel-package-tools
Version ^1.16.4
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform