Package Health

phoenixfire296/laravel-attachments

The MIT license, clear README, matching repository, and release notes improve transparency for consumers. There are no install-time scripts, but the project lacks tests and security scanning, leaving little evidence of ongoing quality assurance.

Latest 1.0.7.2PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has 26 releases, but none in the last 12 months and its latest release was over 7 years ago, which is strong evidence of abandonment risk.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers during the last 3 months, consistent with the long release gap and limited maintenance capacity.

Repo popularitycaution

The repository has 0 stars and 0 forks, with 1 watcher. Popularity is supporting evidence rather than a verdict, but these counts provide little external evidence of maturity or active use.

Repo toolingcaution

Composer is used as the build tool, but no security-scanning tooling is present, so build provenance is ordinary while security assurance is limited.

Security policycaution

The repository has no security policy and no security-scanning tools, leaving limited visible process for handling vulnerabilities in a package that manages file attachments.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

B&B Web Expertise

Direct Dependencies

DependencyLast ReleaseScore
doctrine/dbal
Version ~2.5
nesbot/carbon
Version ~1.20
illuminate/console
Version 5.7.x|5.6.x|5.5.x
illuminate/routing
Version 5.7.x|5.6.x|5.5.x
illuminate/support
Version 5.7.x|5.6.x|5.5.x

Weekly Downloads

Info

Last Published
7 years ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform