Package Health

schenke-io/laravel-url-cleaner

The workflow audit found a high-confidence bot-condition problem and all six action references are unpinned. The license files and repository tests are useful safeguards, but the declared MIT license conflicts with the detected Apache-2.0 license.

Latest v1.0.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

A license file is present in both the artifact and repository, but the manifest declares MIT while the detected file license is Apache-2.0. That mismatch reduces licensing clarity.

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This adds some installation complexity, but the signal does not show a destructive or unusual action.

Project backingcaution

The registry namespace and repository owner match, but the owner is an individual account rather than an organization, indicating limited visible backing capacity.

Release historycaution

This package has only two releases across about 22 months, with one release in the last year and an interval of about 15 months. That is sparse for a library and raises maintenance concerns.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Combined with the sparse release history, this points to limited recent maintenance capacity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

K.-U. Schenke

Direct Dependencies

DependencyLast ReleaseScore
archtechx/enums
Version ^1.1
—
—
guzzlehttp/guzzle
Version ^7.9
—
—
spatie/laravel-package-tools
Version ^1.30
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform