Package Health

vizra/evals-ui

This is a young but actively developed package with a clear MIT license, a linked organization-owned repository, six releases in 29 days, recent repository activity, repository tests and changelog coverage, and no deprecation or archival indicators. Its v0.3.2 status means it is not yet a stable-major release, and the repository has no recorded security-scanning tooling and does not declare top-level workflow token permissions; zero popularity and a small contributor base also limit external validation. Overall, it appears reasonable to adopt with normal review and upgrade monitoring, but it has not yet demonstrated long-term maturity.

Latest v0.3.2PackagistPackagist

79%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

Six releases over 29 days, with a median interval of about 6 days, show active early development; the short history still leaves long-term maintenance unproven.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity; this is neutral for a very young project but provides little evidence of community support.

Repo popularitycaution

The repository has zero stars, forks, and watchers, so there is no external popularity or adoption evidence to reinforce confidence; this is a weak signal for a package only about a month old.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected, leaving a security-process gap that is relevant to dependency confidence.

Token permissionscaution

The only workflow lacks top-level token permissions, so its effective permissions are less explicit than desirable even though no write permissions were detected.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Aaron Lumsden

Direct Dependencies

DependencyLast ReleaseScore
vizra/evals
Version ^0.3
—
—
livewire/livewire
Version ^3.7|^4.0
—
—
illuminate/support
Version ^12.0|^13.0
—
—
illuminate/contracts
Version ^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform