Package Health

rdp77/veyaz

It includes tests, a matching source repository, an MIT license, and a documented security policy. Maintenance has stopped since February 2024, and the workflow audit found a high-confidence floating container image.

Latest v1.9.9PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-autoload-dump, post-create-project-cmd, and post-root-package-install scripts. These are relevant install-time behavior for a Laravel application template and warrant attention, though the signal alone does not establish unsafe behavior.

Release historycaution

The package has only 2 releases, both apparently ending on February 12, 2024, with no releases in the last 12 months. That long release gap is a real maintenance concern despite the stable version format.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers during the last 3 months, matching the lack of recent releases. The repository is not archived, but there is no observed recent activity to offset the abandonment risk.

Workflow auditcaution

All 8 of 9 analyzed action references are unpinned, and a high-confidence finding reports a container using the floating `latest` tag. No untrusted checkout or script-injection path was found, which limits but does not remove the workflow hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
milon/barcode
Version ^9.0
—
—
laravel/tinker
Version ^2.7
—
—
moneyphp/money
Version ^3.3
—
—
laravel/framework
Version ^9.19
—
—
livewire/livewire
Version ^2.10
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform