Package Health

sextanet/laravel-chile-geo

Maintenance is light, with only three releases over about 20 months and no commits in the last three months. The project has clear documentation, tests in the repository, licensing, and release notes, but its automation uses unpinned actions and broad write permissions.

Latest 0.0.3PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Only three releases have appeared across about 20 months, with one release in the last 12 months and a typical gap of about 230 days. This indicates a small, slow-moving project rather than an actively evolving dependency.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Although a recent release exists, the lack of recent source activity is a meaningful maintenance warning.

Security policycaution

The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself show that the package is unsafe.

Version stabilitycaution

Version 0.0.3 is not a stable major release, so the public API may still change. There is no prerelease labeling, which provides limited additional warning but does not offset the early-stage versioning.

Workflow auditcaution

All 12 analyzed action references are unpinned, and three workflows grant top-level write access. The audit also found a high-confidence bot-condition issue in a pull-request-target workflow; with no untrusted checkout or script injection, this is a serious hygiene concern but not an automatic disqualifier.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

SextaNet

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform