Package Health

vizra/evals

This release appears suitable for adoption with normal caution for a young pre-1.0 package. It has a recent and regular release cadence, substantial recent repository activity, active organizational backing, clear licensing, documentation, a changelog, repository tests, a security policy, and no deprecation or archival indicators. The main concerns are its short 29-day history, limited popularity, lack of detected security-scanning tooling, and an Actions workflow without top-level token permissions; these reduce transparency and operational maturity but do not indicate abandonment. The package is still evolving, so consumers should pin versions and review changes before upgrades.

Latest v0.3.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

The package is only 29 days old with six releases and a median interval of about 6 days, showing active iteration but limited evidence of long-term maintenance.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 0 watchers, so external adoption evidence is limited; this is a supporting concern rather than a health verdict for a new package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a modest gap in automated security hygiene.

Token permissionscaution

The only workflow lacks top-level token permissions, so its effective permissions are less explicitly constrained than recommended, creating a limited CI security-hygiene concern.

Version stabilitycaution

Version v0.3.2 is not yet a stable major release, so the API and behavior may change more readily than in a mature 1.x package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aaron Lumsden

Direct Dependencies

DependencyLast ReleaseScore
laravel/ai
Version ^0.10
—
—
league/csv
Version ^9.0
—
—
illuminate/http
Version ^12.0|^13.0
—
—
illuminate/console
Version ^12.0|^13.0
—
—
illuminate/support
Version ^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform