Package Health

nodesol/laraql

The repository has no security policy, and several workflows grant write access without consistently declaring permissions. An install-time script also adds operational risk, although the package is documented, licensed, tested in the repository, and backed by an organization.

Latest v1.0.16PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Repo commit activitydanger

There were zero commits and zero active maintainers during the last three months, a concrete sign that maintenance activity has recently stalled despite continued registry releases.

Dangerous workflowscaution

One workflow uses pull_request_target, but no untrusted checkout or script-injection patterns were detected across the five analyzed workflows; the remaining concern is limited to the privileged trigger.

Lifecycle scriptscaution

A post-autoload-dump install script runs during Composer installation, creating some supply-chain and installation complexity that consumers should account for.

Repo issue activitycaution

The repository has three open pull requests and only one open issue, but no issues or pull requests were opened or merged in the last month, providing limited evidence of current responsiveness.

Security policycaution

The repository has no SECURITY.md or equivalent security policy, leaving vulnerability reporting and response expectations unclear.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Amer Chaudhary

Direct Dependencies

DependencyLast ReleaseScore
nuwave/lighthouse
Version ^6.66
illuminate/contracts
Version ^10.0|^11.0|^12.0|^13.0
mll-lab/graphql-php-scalars
Version ^6.4
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
5 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform