Package Health

qanna-rsa/expression-engine

This release is usable but still early-stage. It has a valid MIT license, a matching repository with substantial tests and documentation, recent repository activity, no deprecation, no install-time scripts, and benign workflow patterns. However, the project is only 25 days old with two releases, remains on v0.1.0, and shows very thin observed maintenance capacity: one commit from one contributor in the last three months. The absent security policy and unspecified workflow permissions add transparency and hardening gaps, though organization ownership and recent activity provide some compensation.

Latest v0.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

Four runtime dependencies, including Laravel components and Carbon, create a meaningful compatibility surface for a young package, though the profile is not unusually large.

Maintainerscaution

Only one registry publisher is listed, which is a thin publishing base; this is partly mitigated by the repository being organization-owned, but it does not establish multiple active publishers.

Release historycaution

The package is only 25 days old and has two releases, so its maintenance and compatibility record are not yet mature.

Repo bus factorcaution

All recent commits come from one contributor, creating a concentrated bus factor. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced.

Repo commit activitycaution

Only one commit from one active maintainer was observed in the last three months. Recent activity is positive, but the very low volume limits confidence in sustained maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ikageng tladi

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^2.0|^3.0
—
—
illuminate/console
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/support
Version ^10.0|^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
22 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform