Package Health

orthodoxauto/ziggy-without-const

MIT licensing, repository tests, and a changelog provide useful transparency for this small package. Maintenance appears to have stopped after its 2021 releases, while the workflow uses three unpinned actions and the repository has no security policy or scanning.

Latest v2.0PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

70

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has 50 releases but none in about five years, with the latest release issued in July 2021. This strongly lowers confidence in ongoing maintenance, although the repository was pushed more recently than the registry release history.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. This is a modest supply-chain hygiene gap rather than evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For a package that supplies application code, this is a transparency gap, though it is less serious than evidence of unsafe workflow behavior.

Workflow auditcaution

The single workflow was fully analyzed with no trigger or audit findings, but all three action references are unpinned. That leaves dependency versions able to change without a repository change and warrants a hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

CashforCars.io

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version >=5.4@dev

Weekly Downloads

Info

Last Published
5 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform