Package Health

prinsfrank/larastan-architecture-rules

The README, license, and release notes make this small package transparent to adopt. Its maintenance has stopped, with no recent commits or releases, and its workflows use unpinned actions; pin v0.0.4 only if you accept that risk.

Latest v0.0.4PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The latest release was published in May 2023, with no releases in the last 12 months. That long release gap is a meaningful abandonment concern for a dependency.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, reinforcing that development is currently inactive.

Repo popularitycaution

The repository has no stars or forks and only one watcher. Popularity is not decisive for a small rules package, but this provides little supporting evidence of active use or review.

Security policycaution

The repository has no security policy. This is a transparency and response-process gap, though the package's narrow static-analysis scope limits its significance.

Workflow auditcaution

Both analyzed workflows use unpinned actions, so referenced build tooling can change without a fixed version. The audit found no untrusted checkouts, script injection, broad write permissions, or other high-impact findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
phpstan/phpstan
Version ^1.9
—
—
nunomaduro/larastan
Version ^1.0.4 || ^2.4
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform