Package Health

networkrailbusinesssystems/laravel-model-states

Usable with caveats: the package is licensed, backed by an organization, tested in its repository, and not deprecated. However, it has only one release and no commits or active maintainers recorded in the last three months, with some GitHub workflow permission concerns.

Latest 1.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dangerous workflowscaution

One of three workflows uses pull_request_target, which requires elevated trust because it can run with repository privileges, although no untrusted checkout or script-injection pattern was detected.

Release historycaution

This package is 178 days old but has only one release, so there is little release history to demonstrate sustained maintenance or compatibility handling.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, which is a meaningful maintenance concern for a package with only one release.

Repo popularitycaution

The repository has zero stars and one fork, offering little community validation; this is supporting evidence only and is partly expected for a newly published package.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Brent Roose

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^12.0|^13.0
—
—
illuminate/database
Version ^12.0|^13.0
—
—
illuminate/contracts
Version ^12.0|^13.0
—
—
facade/ignition-contracts
Version ^1.0.2|^2.0
—
—
spatie/php-attribute-reader
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform