Package Health

stepanenko3/laravel-system-resources

MIT licensing, release notes, and a repository that clearly matches the package support transparency. The single-maintainer project shows limited recent activity, and all three workflow actions are unpinned.

Latest v1.1.1PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

One registry maintainer creates a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is no provided compensating backing signal.

Release historycaution

The package has only four releases, with none in the last 12 months and the latest published about 2 years 6 months ago. This indicates slowing maintenance, although the repository was pushed more recently than the last registry release.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. That weakens evidence of ongoing maintenance for a package whose latest registry release is already about 2 years 6 months old.

Security policycaution

No repository security policy was found, which is a modest transparency gap for vulnerability reporting. The repository does use Dependabot, providing some compensating security tooling.

Workflow auditcaution

The single workflow was fully analyzed with no injection or high-severity findings, but all 3 action references are unpinned, leaving build inputs less reproducible. The absence of a top-level permissions block is not a concern by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Artem Stepanenko

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version ^9.0|^10.0|^11.0

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform