Package Health

olivermbs/laravel-enumshare

This release shows strong current development and reasonable engineering hygiene: it is stable, recently released, actively committed to, tested in the repository, licensed, and supported by CI/security tooling. However, Packagist marks the package as abandoned and points to olivermbs/enumshare as its replacement, which is a severe adoption concern even though the linked repository is currently active; the repository also does not match the package name or mention the package in its README, creating additional provenance ambiguity. The single-maintainer, single-contributor profile further increases continuity risk, so this package should not be adopted without resolving the abandonment and repository-identity issues.

Latest v1.3.1PackagistPackagist

40%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Registry deprecationdanger

Packagist reports the package as abandoned and specifies a replacement package, which is a severe transparency and adoption risk. Recent releases do not compensate for an explicit registry-level abandonment marker.

Dangerous workflowscaution

One of five workflows uses pull_request_target, which carries elevated workflow risk, but there are no untrusted checkouts or script-injection findings in the analyzed workflows.

Lifecycle scriptscaution

The package uses a post-autoload-dump lifecycle script. This warrants review because installation-time execution expands supply-chain exposure, although the signal alone does not establish that the script is unsafe.

Maintainerscaution

Only one registry maintainer is listed, which creates publishing continuity risk; the active repository does provide some compensation, but it remains dependent on one person.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the single-maintainer and single-contributor risks.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Oliver Smith

Direct Dependencies

DependencyLast ReleaseScore
symfony/finder
Version ^6.0||^7.0||^8.0
illuminate/console
Version ^11.0||^12.0||^13.0
illuminate/contracts
Version ^11.0||^12.0||^13.0

Weekly Downloads

Info

Last Published
12 days ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform