Package Health

schaefersoft/laravel-llms-txt

This release appears suitable to depend on: it is a stable 1.3.0 release with nine releases over 161 days, recent repository activity, merged pull requests, a non-archived source repository, repository tests and changelog coverage, and clear MIT licensing. The main reservations are the young project age, low popularity, concentrated recent commits, absent security policy and security-scanning tooling, and incomplete GitHub Actions permission declarations; however, the organization-owned repository, active second contributor, safe workflow analysis, and ongoing release cadence provide meaningful mitigation. The package artifact is minimal and omits its README, tests, and changelog, but those materials are present in the source repository, so this is primarily a distribution-hygiene gap rather than an abandonment signal.

Latest 1.3.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

Two contributors were active, but the top contributor made about 78% of recent commits. This is concentrated activity, though organization ownership provides some ability to hand maintenance off.

Repo popularitycaution

The repository has seven stars and two forks, indicating limited adoption. Popularity is only supporting evidence, so this modest reach lowers confidence in maturity but does not by itself make the package unsafe to use.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The missing scanning is a security-hygiene gap, although it is not evidence of abandonment.

Security policycaution

The repository has no security policy. This reduces disclosure transparency and is a genuine project-hygiene gap, particularly for a package intended to be used as a dependency.

Token permissionscaution

One workflow lacks top-level permissions and the release workflow grants top-level write access. These declarations are less restrictive than ideal and increase CI permission risk, although the separate workflow-risk analysis found no dangerous workflow pattern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

SchaeferSoft

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^10.0|^11.0|^12.0|^13.0
illuminate/cache
Version ^10.0|^11.0|^12.0|^13.0
guzzlehttp/guzzle
Version ^7.15.2 || ^8.0.1
illuminate/console
Version ^10.0|^11.0|^12.0|^13.0
illuminate/routing
Version ^10.0|^11.0|^12.0|^13.0

Weekly Downloads

Info

Last Published
16 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform