Package Health

spits-online/laravel-openprovider-api

The package has clear documentation, tests in the repository, a license, and recent contributions from two active contributors. Workflow hygiene needs attention, especially broad permissions, unpinned actions, and a high-confidence bot-condition finding; releases are also infrequent.

Latest v1.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package uses a post-autoload-dump install-time script. This is a mild supply-chain and installation-complexity concern, though the signal does not show a dangerous script or additional behavior.

Release historycaution

The package has only 3 releases over 483 days, with a median interval of about 231 days. The latest release was published recently, which reduces abandonment concern but does not offset the slow overall cadence entirely.

Repo commit activitycaution

The repository recorded 2 commits in the last 3 months, with 2 active maintainers. This is limited activity, but the recent release and active contributors provide some compensation.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting expectations unclear.

Workflow auditcaution

All 4 workflows were analyzed, but all 9 action references are unpinned, 2 workflows grant top-level write permissions, and a high-confidence bot-conditions finding was reported in the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a hygiene concern rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Spits

Direct Dependencies

DependencyLast ReleaseScore
maatwebsite/excel
Version ^3.1||^4.0
—
—
illuminate/support
Version ^11.0||^12.0||^13.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform