Package Health

smart-dato/inpost-sdk

A Laravel SDK for the InPost API — Shipping, Points, Tracking, Returns, and Pickups

Latest v0.0.10PackagistPackagist

72%

Total Score

caution

Usable with caveats: active project, but one contributor and a high-confidence CI check concern reduce confidence.

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install lifecycle script, which adds execution during installation; this is a mild supply-chain hygiene concern, though only one standard Composer hook is declared.

Repo bus factorcaution

All four recent commits came from one contributor, creating a thin operational base; organization ownership provides some capacity to hand maintenance off but does not remove the concentration risk.

Version stabilitycaution

v0.0.10 is not a stable major release, so its public API may still change despite the absence of prerelease markers.

Workflow auditcaution

All five workflows were analyzed, all 11 action references are pinned, and no untrusted checkout or script injection was found. However, a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow, and two workflows grant top-level write permissions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

SmartDato

Direct Dependencies

DependencyLast ReleaseScore
spatie/laravel-data
Version ^4.20
—
—
illuminate/contracts
Version ^11.0||^12.0||^13.0
—
—
saloonphp/laravel-plugin
Version ^4.0||^5.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform