Package Health

saucebase/installer

This release appears usable and reasonably healthy for dependency adoption: it is non-deprecated, stable, actively released, backed by a non-archived organization-owned repository, and includes a substantial README, tests, CI, and release workflows. The main risks are the package's young 79-day history, extreme concentration of commits in one contributor despite a second active contributor, absent security policy, and incomplete GitHub Actions permission hardening; these warrant review before relying on it for critical infrastructure but do not indicate abandonment or an otherwise unfit package.

Latest v2.8.1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

The package declares 12 runtime dependencies for a CLI that integrates Laravel, Composer, prompts, HTTP, filesystem, and process functionality; this is a meaningful dependency surface to maintain, but it is consistent with the described installer role.

Release historycaution

The package is young at 79 days, which limits demonstrated longevity, but 26 releases in that period with a median interval of about 21 minutes shows very active development rather than abandonment.

Repo bus factorcaution

Two contributors were active, but one made 46 of 47 commits, creating substantial maintainer concentration. The organization-owned repository provides some ability to hand off maintenance, so this is a caution rather than a severe risk.

Repo popularitycaution

The repository has zero stars, forks, and watchers, indicating little visible adoption or external validation; popularity is only supporting evidence, so this lowers confidence more than it determines health.

Repo toolingcaution

Composer is used as the build tool, but no security scanning tools were detected. Build tooling is present; the missing security automation is a modest supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^13.0
laravel/prompts
Version ^0.3
symfony/process
Version ^8.0
guzzlehttp/guzzle
Version ^7.8
illuminate/events
Version ^13.0

Weekly Downloads

Info

Last Published
18 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform