Package Health

solution-forest/filament-goaccess

The organization provides some handoff capacity, and the release includes tests, notes, and a clear README. Its short history and one-contributor record leave maintenance less proven, while all seven workflow actions are unpinned.

Latest v1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is a young package, first released 59 days ago, with only one release and no established release cadence. That limits evidence of long-term maintenance.

Repo bus factorcaution

All four recent commits come from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

Four commits from one active maintainer in the last three months show initial development activity, but the small amount of activity provides limited evidence of ongoing support.

Security policycaution

No repository security policy was found. This is a transparency gap for reporting and handling security issues, though it is not evidence of maliciousness.

Workflow auditcaution

Both workflows were fully analyzed with no untrusted checkouts, script injection, or auditor findings. However, all seven action references are unpinned, and one workflow grants top-level write permissions, creating avoidable supply-chain and token-scope risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Solution Forest

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.0|^5.0
illuminate/contracts
Version ^11.0|^12.0|^13.0
spatie/laravel-package-tools
Version ^1.16

Weekly Downloads

Info

Last Published
2 months ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform