Package Health

networkrailbusinesssystems/support-page

This release appears healthy and suitable for dependency use: it has frequent recent releases, a stable non-prerelease version, an active and non-archived repository, comprehensive source tests, a clear README, an MIT license, and no install-time lifecycle scripts. The main concerns are that all recent repository commits come from one contributor and the repository lacks a security policy and explicit workflow token permissions; these are meaningful transparency and continuity gaps, although organization ownership and otherwise active maintenance reduce the abandonment concern. Repository popularity is very low, but that is only supporting evidence and does not outweigh the strong maintenance and package-structure signals.

Latest 5.1.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

One contributor made all 8 commits in the last 3 months, a genuine single-contributor continuity risk; organization ownership provides some ability to hand off maintenance but does not itself show a second active contributor.

Repo commit activitycaution

The repository recorded 8 commits in the last 3 months, demonstrating recent activity, but all activity is concentrated in one active maintainer, leaving continuity dependent on that contributor.

Repo popularitycaution

The repository has 0 stars, 1 fork, and 1 watcher, indicating little public adoption. This is weak supporting evidence only and is outweighed by the package's active release history, tests, and organization backing.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap, though the package still has active releases, tests, and repository workflows.

Security policycaution

No repository security policy was found, reducing transparency around vulnerability reporting and response procedures; this is a maintenance and security-process gap rather than evidence of maliciousness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sim Roberts

Direct Dependencies

DependencyLast ReleaseScore
laracasts/flash
Version ^3
—
—
illuminate/support
Version ^13
—
—
spatie/laravel-permission
Version ^6
—
—
anthonyedmonds/govuk-laravel
Version ^8
—
—
anthonyedmonds/laravel-form-builder
Version ^2
—
—

Weekly Downloads

Info

Last Published
21 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform