Package Health

wsssoftware/laravue-toolkit

The repository is well matched to the package and includes a license, tests, a changelog, release notes, and automated security tooling. Organization backing is reassuring, but pinning this exact version limits exposure to future changes.

Latest 2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has 22 releases since September 2022, but none in the last two years; the latest release was in May 2024. This is a meaningful maintenance concern for a toolkit with ongoing dependencies.

Repo commit activitycaution

The repository had 0 commits and 0 active maintainers in the last three months, consistent with the long release gap. The project is not archived, but current maintenance activity is absent.

Security policycaution

The repository has no published security policy. This is a transparency and vulnerability-reporting gap, though Dependabot scanning provides some compensating security tooling.

Workflow auditcaution

All 6 action references are unpinned, and the audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, which limits the severity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Allan Carvalho

Direct Dependencies

DependencyLast ReleaseScore
linfo/linfo
Version ^4.0.7
—
—
composer/composer
Version ^2.4.2
—
—
czproject/git-php
Version ^4.0.5
—
—
illuminate/contracts
Version ^10.0|^11.0
—
—
spatie/laravel-package-tools
Version ^1.9.2
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform