Package Health

sofa/laravel-artisan-log

The repository has four stars and one registry maintainer, limiting visible support capacity. It includes tests, a README, an MIT license, and no install scripts, but its workflow uses unpinned actions.

Latest 1.0.5PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has six releases since May 2020 but none in the last three years, indicating a likely inactive release process. Its stable 1.0.5 version and short historical release intervals partly offset the concern.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.

Repo popularitycaution

Four stars, one fork, and one watcher indicate a very small public user base, so there is limited visible community support. Low popularity is supporting evidence rather than a standalone failure.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations. This is a hygiene gap, not evidence that the package is unsafe.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions modestly reduce build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jarek Tkaczyk

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
—
—
illuminate/console
Version >=7.0
—
—
illuminate/support
Version >=7.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform