Package Health

roundly-consulting/comments-for-laravel

Documentation and release notes make the feature set easy to assess. It is a brand-new release with one registry maintainer and all recent commits from one contributor, while organization backing and active development reduce the concern.

Latest 1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Dependency profilecaution

Eight runtime dependencies create meaningful coupling, but they are coherent Laravel ecosystem packages from the same organization rather than unexplained or unusually broad dependencies.

Release historycaution

The package was released only 0 days ago and has a single release, so there is no track record yet for maintenance or compatibility over time.

Repo bus factorcaution

All 29 recent commits came from one contributor, creating a meaningful continuity risk if that person becomes unavailable.

Workflow auditcaution

All three workflows were analyzed with no dangerous audit findings or untrusted checkouts. However, all 9 action references are unpinned, so workflow dependencies remain a supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andrej Mihaliak

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^12.0|^13.0
—
—
roundly-consulting/enums-for-laravel
Version ^1.0
—
—
roundly-consulting/likes-for-laravel
Version ^1.0
—
—
roundly-consulting/reports-for-laravel
Version ^1.0
—
—
roundly-consulting/approvals-for-laravel
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
2 hours ago
Created
2 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform