Package Health

patchlevel/laravel-event-sourcing

Recent releases and a matching, well-tested source tree add useful confidence. The main limitations are concentrated recent activity, no security policy or scanning, and unpinned workflow actions.

Latest 1.4.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script, which adds a modest execution concern even though only one standard Composer lifecycle hook is present.

Repo bus factorcaution

All recent commits came from one contributor. Organization backing provides some handoff capacity, but no second recently active contributor is shown.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, which is modest activity, though the repository was recently updated and the release history remains active.

Repo toolingcaution

The project uses Composer and Make, but no security scanning tools were detected, leaving a maintenance and security-process gap.

Security policycaution

The repository has no SECURITY.md or other detected security policy, reducing transparency for reporting and handling vulnerabilities.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Badura
David Badura

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0 || ^12.0 || ^13.0
patchlevel/event-sourcing
Version ^3.15.0

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform