Package Health

thethunderturner/laravel-tmdb

The package includes a matching MIT license, clear documentation, repository tests, security policy, and automated dependency scanning. Its Composer setup and pinned workflow actions are reassuring, but longer-term maintenance is not yet demonstrated.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Project backingcaution

The repository is owned by the same individual namespace as the package, so ownership is consistent; individual ownership also means the visible maintainer base is limited.

Release historycaution

Only one release exists and the package is 0 days old, so there is no historical release cadence to establish reliability or maintenance continuity.

Repo commit activitycaution

The repository has no commits or active maintainers recorded over the last 3 months, but the package is newly released, so this primarily reflects insufficient history rather than demonstrated abandonment.

Workflow auditcaution

Both workflows were analyzed successfully, all five action references are pinned, and no audit findings or untrusted checkout paths were found. One workflow grants top-level write permission, which is a mild hygiene concern but has no corroborating untrusted trigger or sink.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Matthew Biskas

Direct Dependencies

DependencyLast ReleaseScore
php-tmdb/api
Version ^4.1
—
—
guzzlehttp/psr7
Version ^2.9|^3.0
—
—
guzzlehttp/guzzle
Version ^7.8|^8.0
—
—
illuminate/support
Version ^12.0||^13.0
—
—
symfony/event-dispatcher
Version ^7.0|^8.0
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform