Package Health

nexxai/laravel-rfc3161

The package is licensed, documented, and backed by repository tests, with seven releases in about five months. Maintenance depends on one contributor, while CI has unpinned actions and a medium-confidence actor check; no security policy is published.

Latest v2.2.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry publishing account is listed; because the repository is also owned by an individual, there is no organization-backed handoff evidence to offset that concentration.

Repo bus factorcaution

One contributor made all three recent commits, leaving maintenance continuity dependent on a single person.

Repo commit activitycaution

Three commits in the last three months show some ongoing work, although the activity is modest for a young package.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

All seven action references are unpinned, and the audit found a medium-confidence high-severity bot-condition issue. The workflow uses job-level permissions and has no untrusted checkout or script-injection finding, which limits but does not remove the CI risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

JT Smith

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^11.0||^12.0||^13.0
—
—
symfony/process
Version ^7.2||^8.0
—
—
illuminate/support
Version ^11.0||^12.0||^13.0
—
—
illuminate/database
Version ^11.0||^12.0||^13.0
—
—
illuminate/contracts
Version ^11.0||^12.0||^13.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform