Package Health

saade/filament-adjacency-list

This is a generally healthy, actively maintained release with a clear MIT license, a matching repository, substantial documentation, repository tests and changelog coverage, ongoing releases, and no registry deprecation or archival status. The main concerns are that recent repository activity is very concentrated in one contributor, with only one commit in the last three months, and that several workflows use broad write permissions; these increase maintenance and CI supply-chain exposure but do not outweigh the package’s consistent release history and repository hygiene. It is a reasonable dependency, with normal diligence around future maintenance and updates advised.

Latest v4.1.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One of five workflows uses pull_request_target, which carries elevated CI trust risk, but no untrusted checkout or script-injection patterns were detected.

Lifecycle scriptscaution

The package uses a post-autoload-dump install lifecycle script. This adds some installation complexity and execution surface, though the signal does not indicate an unusually dangerous script.

Maintainerscaution

Only one registry account, Saade, has publishing access. This is a modest publishing-resilience concern, although repository activity and ownership are consistent with that maintainer.

Project backingcaution

The linked repository is owned by the individual user Saade rather than an organization, so the concentrated maintainer and commit activity is not compensated by evident organizational handoff capacity.

Repo bus factorcaution

All recent commits came from one contributor with a 100% share, creating a genuine single-maintainer continuity risk; the repository is user-owned rather than organization-owned, so there is no organizational backing to offset it.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Saade

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.0|^5.0
—
—
illuminate/contracts
Version ^11.0|^12.0|^13.0
—
—
spatie/laravel-package-tools
Version ^1.15.0
—
—
staudenmeir/laravel-adjacency-list
Version ^1.18
—
—
ryangjchandler/blade-capture-directive
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
25 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform