Package Health

spatie/security-advisories-health-check

Healthy and suitable to depend on. It has a recent stable release, active repository maintenance, clear licensing, tests in the source repository, and organizational backing; workflow permission gaps and the absence of a security policy are minor caveats.

Latest 1.3.2PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One of four workflows uses pull_request_target for Dependabot auto-merge, which deserves review because that trigger can expose elevated workflow context. However, no untrusted checkouts or script-injection patterns were detected.

Security policycaution

The repository has no SECURITY.md or other detected security policy. This is a transparency gap, although the package does use Dependabot and the absence does not by itself indicate abandonment.

Token permissionscaution

Three of four workflows lack top-level permission declarations, and one workflow grants top-level write access. Explicit least-privilege declarations would improve repository hygiene, though this concerns project automation rather than normal package use.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Freek Van der Herten

Direct Dependencies

DependencyLast ReleaseScore
spatie/packagist-api
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform