Package Health

vocalio/laravel-cart

A valid MIT license, repository tests, release notes, and Dependabot support improve the baseline. GitHub workflow hygiene is weaker than the package documentation and ownership signals, so pin this version and watch for maintenance updates.

Latest 0.1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has only one release, published 564 days ago, with no releases in the last 12 months. That limited history provides little evidence of sustained maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is meaningful evidence of weak recent maintenance.

Security policycaution

The repository has no security policy. This is a transparency gap for a package that handles application data, though it is not evidence of a security defect by itself.

Version stabilitycaution

Version 0.1 is not a stable major release, although it is not marked as a prerelease. The early version increases API and maturity uncertainty.

Workflow auditcaution

All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. No untrusted checkout or script-injection sink was found, so this is a hygiene and maintenance concern rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Vocalio

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^11.0|^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform