Package Health

sfolador/laravel-eloquent-toggle

No commits were recorded in the last three months, and the workflow audit found a high-confidence bot-condition issue plus entirely unpinned actions. The matching repository, tests, license, README, and security tooling provide useful transparency.

Latest 0.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has only one release, published about 3 years and 9 months ago, with no releases in the last 12 months. A recent repository push partly offsets this, but registry maintenance is still weak.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. This suggests current maintenance may be inactive despite the repository not being archived.

Security policycaution

The linked repository has no security policy. This reduces vulnerability-reporting transparency, though Dependabot provides some compensating security tooling.

Version stabilitycaution

Version 0.1 is not a stable major release, which signals limited maturity. It is not marked as a prerelease, so the concern is moderate rather than severe.

Workflow auditcaution

All 12 analyzed action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull request trigger has no untrusted checkout or script-injection sink, limiting the impact to workflow hygiene and maintenance risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

sfolador

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^2.64
illuminate/contracts
Version ^9.0
spatie/laravel-package-tools
Version ^1.13.0

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform