Package Health

schmeits/pulse-panphp

A Laravel Pulse card displaying PanPHP analytics

Latest 0.0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

This is the sole release, published about 1 year 11 months ago, with no releases in the last 12 months. That makes the package's release maintenance look stale despite recent repository activity.

Repo bus factorcaution

All recent commits came from one contributor, giving the project a concentrated maintenance base. With user-owned rather than organization-backed ownership, there is little demonstrated redundancy if that contributor stops maintaining it.

Repo commit activitycaution

The repository recorded one commit in the last 3 months from one active maintainer. This shows some current activity, but the very low pace provides limited evidence of sustained maintenance.

Version stabilitycaution

Version 0.0.1 is an early, non-stable-major release, so its API and behavior may still change substantially. The GitHub release and release notes provide some transparency but do not offset the immature versioning.

Workflow auditcaution

The audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow, and three workflows grant top-level write permissions. There are no untrusted checkouts or script-injection findings, so this is a workflow-hygiene concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tally Schmeits

Direct Dependencies

DependencyLast ReleaseScore
panphp/pan
Version ^0.1.3
—
—
laravel/pulse
Version ^1.2
—
—
illuminate/contracts
Version ^11.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform