Package Health

pepeiborra/traffic-reader

This is a usable but still young package with clear licensing, documentation, tests, changelog, a complete-looking 17-file artifact, stable versioning, and a non-archived repository that matches and documents the package. However, it has only 140 days of history and three releases, repository commit activity reports no commits or active maintainers in the last three months, and the project has only one registry maintainer. The absence of security-policy and security-scanning tooling is an additional transparency gap. Recent release and push timestamps provide some evidence of ongoing publishing, but the package remains a moderate-maintenance-risk dependency rather than a mature, well-established one.

Latest 1.2PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Dependency profilecaution

Six runtime dependencies create meaningful integration and transitive-maintenance surface for a Laravel middleware package, though the profile is not inherently excessive or clearly unsafe.

Maintainerscaution

Only one registry account has publish access, limiting publishing redundancy. The linked repository is user-owned rather than organization-owned, and no broader maintainer capacity is shown.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no demonstrated organizational backing or redundancy. This is a modest resilience concern, not a severe risk on its own.

Release historycaution

The package is young at 140 days and has only three releases, so its long-term maintenance record is limited. The latest release was published recently, which partially offsets the short history but does not establish maturity.

Repo commit activitycaution

The repository reports zero commits and zero active maintainers over the last three months, a significant maintenance and abandonment concern. The recent release and repository push show publishing activity, but they do not demonstrate sustained development capacity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pepe Iborra

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/cache
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/events
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/support
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/notifications
Version ^10.0|^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
16 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform