Package Health

oi-lab/oi-laravel-changelogs

Usable with caveats: it has clear licensing, documentation, tests in the repository, and organization-backed source that matches the package. However, this is the first release with no demonstrated maintenance history, and its workflow lacks explicit token permissions and security scanning.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install-time script runs during dependency setup. The signal does not show that it is harmful, but lifecycle execution adds a maintenance and review consideration.

Release historycaution

This is the first release and was published only hours ago, so there is no release track record or evidence of sustained maintenance yet.

Repo commit activitycaution

The repository has no commits or active maintainers recorded in the last three months, although the repository was created or pushed only hours before this assessment, so this mainly reflects the package's extreme newness.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap in the source project.

Security policycaution

No repository security policy is present, reducing transparency about how vulnerability reports would be handled.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

OI Lab

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^6.0|^7.0|^8.0
illuminate/http
Version ^11.0|^12.0|^13.0
illuminate/cache
Version ^11.0|^12.0|^13.0
league/commonmark
Version ^2.0
illuminate/console
Version ^11.0|^12.0|^13.0

Weekly Downloads

Info

Last Published
2 days ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform