Package Health

wsmallnews/category

This is a reasonably healthy but relatively young package with a clear MIT license, 15 releases over 312 days, regular recent commits, a matching and maintained repository, changelog and README coverage, security policy, and Dependabot scanning. The main adoption risks are that all 21 recent commits came from one contributor, the repository has no tests despite having CI scaffolding, repository popularity is negligible, and several workflows grant write permissions; these concerns warrant caution but do not indicate abandonment or an unfit dependency.

Latest v1.0.12PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

One of four workflows uses pull_request_target for Dependabot auto-merge. No untrusted checkout or script-injection findings were observed, but this privileged workflow pattern merits review.

Lifecycle scriptscaution

The package uses a post-autoload-dump lifecycle script. This is an install-time execution surface that deserves review, but the signal alone does not establish an unhealthy package.

Maintainerscaution

Only one registry account has publish access. This is a concentration risk, although repository activity shows that the same project is actively releasing and committing.

Package scaffoldingcaution

A substantial README and changelog are present, and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. For a framework-integrated package, the lack of observed tests is a genuine maintenance concern despite the surrounding documentation and CI configuration.

Project backingcaution

The repository is owned by the Wsmallnews user account rather than an organization, so there is no organizational backing to compensate for concentrated maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

smallnews

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.0 || ^5.0
—
—
wsmallnews/support
Version ^1.0
—
—
guava/filament-icon-picker
Version ^3.0 || ^4.0
—
—
spatie/laravel-package-tools
Version ^1.15.0
—
—
wsmallnews/filament-nestedset
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform