Package Health

robot-council/core

The project is only three days old, despite 18 releases, so its long-term stability is unproven. Active commits, two balanced contributors, release notes, tests in the repository, and organization backing provide meaningful support.

Latest v0.6.10PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install lifecycle script. This deserves some review because install-time code executes automatically, but the signal alone does not show unsafe behavior.

Release historycaution

The package is only 3 days old but already has 18 releases, with a median interval of about 29 minutes. This shows active iteration, but provides little evidence of long-term stability.

Security policycaution

No security policy is present in the repository. For a package handling GitHub sign-in, tokens, and agent sessions, this is a transparency gap.

Version stabilitycaution

Version v0.6.10 is not a stable major release, although it is not marked as a prerelease and recent releases contain no prereleases. The 0.x version still signals an evolving API.

Workflow auditcaution

The single workflow has read-only permissions and no audited dangerous findings, but all 21 action references are unpinned. That leaves the build exposed to moving action versions and is a workflow hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

joshdaugherty

Direct Dependencies

DependencyLast ReleaseScore
laravel/mcp
Version ^1.0
—
—
laravel/sanctum
Version ^4.3.1
—
—
laravel/socialite
Version ^5.31.0
—
—
livewire/livewire
Version ^4.2.0
—
—
illuminate/contracts
Version ^13.23.0
—
—

Weekly Downloads

Info

Last Published
43 minutes ago
Created
8 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform