Package Health

samuelterra22/laravel-report-generator

The package has a substantial README, repository tests, a changelog, and active security tooling. Its single-maintainer structure, sparse release history, recent lack of commits, and workflow weaknesses warrant pinning and monitoring.

Latest v1.0.1PackagistPackagist

66%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

25

Health Score Breakdown

Workflow auditdanger

All 14 analyzed action references are unpinned, creating avoidable workflow supply-chain drift. The audit also found one high-confidence bot-conditions issue in the Dependabot auto-merge workflow; the pull_request_target trigger had no untrusted checkout or script-injection sink, so this is serious hygiene risk rather than a standalone package verdict.

Maintainerscaution

Only one account has registry publish access, which limits publishing redundancy. The repository is user-owned rather than organization-backed, so there is no provided organizational capacity to offset that limitation.

Release historycaution

The package has only two releases across roughly eight years, with one release in the last 12 months and a median interval of about 7.7 years. The recent release helps, but the long gaps indicate limited release maturity.

Repo commit activitycaution

The repository records zero commits and zero active maintainers in the last three months. Although it was pushed recently and the release included changes, the current commit inactivity limits confidence in ongoing maintenance.

Security policycaution

The repository has no documented security policy. This is a transparency gap for reporting vulnerabilities, though the repository's automated security scanning partly offsets the broader security-process concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Samuel Terra

Direct Dependencies

DependencyLast ReleaseScore
maatwebsite/excel
Version ^3.1
—
—
illuminate/support
Version ^10.0||^11.0||^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform