Package Health

wongyip/laravel-renderable

This release is usable but carries meaningful maintenance and transparency concerns. It has a stable v1.4.0 line, 58 releases over roughly 4.8 years, a non-deprecated registry status, a matching source repository, and no install-time lifecycle scripts. However, the repository shows no commits or active maintainers in the last 3 months, has no tests, changelog, security policy, or security scanning, and the package has no declared or file-based license. A single registry publisher and very low repository popularity further limit evidence of sustained project support, so depend on it only if its functionality is important and you can accept or mitigate maintenance risk.

Latest v1.4.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Licensedanger

No declared license and no license file were found in the artifact or repository. This is a genuine adoption and transparency concern because downstream users may lack clear permission to use, modify, or redistribute the code.

Repo commit activitydanger

There were 0 commits and 0 active maintainers in the last 3 months. This is the strongest maintenance concern in the assessment because it suggests current development has stalled, even though the registry shows recent releases.

Dependency profilecaution

Seven runtime dependencies, including Laravel, Twig, helper packages, HTML utilities, and HTML Purifier, create a relatively broad dependency surface for a small rendering package. This is a manageable but real compatibility and transitive-maintenance consideration.

Maintainerscaution

Only one registry account has publish access. That limits publishing redundancy, although this administrative signal does not establish actual maintenance activity or prove abandonment.

Package scaffoldingcaution

The package has a substantial README, but neither the artifact nor repository contains tests or a changelog, leaving behavior and release-history verification weaker. The README documents the package's Laravel rendering purpose, but does not compensate for the absent validation artifacts.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wongyip

Direct Dependencies

DependencyLast ReleaseScore
laravel/framework
Version *
rcrowe/twigbridge
Version *
wongyip/html-tags
Version *
wongyip/phphelpers
Version *
ezyang/htmlpurifier
Version ^4.17

Weekly Downloads

Info

Last Published
16 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform