Package Health

robyajo/pasak

Pasak - enterprise-grade headless self-hosted WAF, threat detection engine, zero-tolerance blocking, stepped login lockout, and security auditing toolkit for Laravel.

Latest v1.1.8PackagistPackagist

58%

Total Score

caution

Twenty releases appeared within one day, while the repository shows no commits in three months and all six workflow actions are unpinned.

Health Score Breakdown

Maintainerscaution

One registry maintainer is consistent with this user-owned repository, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.

Project backingcaution

The repository is owned by a user account rather than an organization, so there is no provided evidence of institutional backing to compensate for the single-maintainer profile.

Release historycaution

Twenty releases were published within one day, with a median interval of about 4 minutes; this shows active publishing but provides little evidence of an established release cadence.

Repo commit activitycaution

The repository records zero commits and zero active maintainers in the last three months; because the package is newly published, this is partly explained by its age but still leaves maintenance capacity unproven.

Workflow auditcaution

The workflow audit found no dangerous triggers, untrusted checkouts, injection findings, or write-wide permissions, and one workflow scopes permissions read-only. However, all 6 of 6 action references are unpinned, weakening build reproducibility and action supply-chain control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Roby

Direct Dependencies

DependencyLast ReleaseScore
illuminate/auth
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/http
Version ^10.0|^11.0|^12.0|^13.0
—
—
guzzlehttp/guzzle
Version ^7.8|^8.0
—
—
illuminate/console
Version ^10.0|^11.0|^12.0|^13.0
—
—
illuminate/routing
Version ^10.0|^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
3 hours ago
Created
6 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform