Package Health

otatechie/laravel-spotlight

Usable with caveats: the package is clearly backed by a matching repository with documentation, tests, releases, and sensible dependencies. However, it has had no commits or active maintainers for about five months, while workflow permissions and the lack of a security policy add maintenance and transparency concerns.

Latest v1.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script injection was detected, but this privileged workflow deserves review before relying on the repository's automation.

Release historycaution

All three releases occurred within about two days, and there has been no new registry release for roughly eight months. This shows an initial release burst but limited evidence of sustained release maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a significant warning for a diagnostics tool that may need updates as Laravel and security practices change.

Security policycaution

The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities in a package that advertises security analysis.

Token permissionscaution

Two workflows grant top-level write permissions and two omit top-level permission declarations, which is weaker least-privilege hygiene than expected for repository automation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

otatechie

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0||^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform