Package Health

wrkflow/larastrict

The project has no security policy, and its workflows leave most action references unpinned while inheriting secrets. Tests, changelog, release notes, and a matching organization repository provide useful transparency.

Latest v0.0.93PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 93 releases since September 2022, but none in the last 12 months and its latest release was about 20 months ago. This materially raises maintenance and abandonment concerns.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, despite the repository not being archived. That is strong evidence of currently inactive development.

Repo issue activitycaution

There are 48 open issues, with one new issue and no issues or pull requests closed in the last month. This suggests a backlog with limited visible response activity.

Security policycaution

The linked repository has no security policy. For a Laravel framework extension, this reduces transparency around vulnerability reporting and response.

Workflow auditcaution

All 10 analyzed action references are unpinned, and high-confidence medium-severity findings show workflows inheriting secrets. No untrusted checkout or script-injection paths were found, which limits the risk but does not remove the workflow hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Martin Kluska

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2 | ^3
—
—
psr/simple-cache
Version ^3.0
—
—
laravel/framework
Version ^9
—
—
h4kuna/serialize-polyfill
Version ^0.2.5
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform