Package Health

slashequip/laravel-patchable

Usable with caveats: the package is licensed, transparently sourced, tested in the repository, and not deprecated, but it has had only one registry release with no commits in the last three months. A single maintainer and permissive GitHub workflow settings add maintenance and operational risk.

Latest v1.0.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One workflow uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection pattern was detected, so this is a workflow caution rather than a severe health risk.

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script, which adds some installation complexity and trust exposure, though this alone is not evidence that the package is unsafe to depend on.

Maintainerscaution

Only one registry publishing account is listed, creating a narrow operational base if that maintainer becomes unavailable. The linked repository is user-owned rather than organization-owned, so there is no organization backing shown to offset this concern.

Project backingcaution

The registry namespace and repository owner match, but the owner is an individual user rather than an organization, so the evidence shows direct ownership without broader institutional backing.

Release historycaution

Only one release has been published, and it was approximately 17 months before collection, leaving little evidence of sustained release maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sam Jones

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0||^12.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform