Package Health

xgrz/money

The package has clear documentation, tests, a stable release line, and a small runtime dependency set. Recent repository commits are absent despite frequent releases, while the sole maintainer and unpinned workflow actions add modest continuity and build-integrity concerns.

Latest v2.0.8PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry maintainer is listed, creating a thin publishing base and higher continuity risk. The linked repository is owned by the same individual, so there is no separate organizational backing to compensate for that concentration.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last three months, which weakens evidence of ongoing source maintenance. Recent registry releases and a recent repository push partly offset this concern, but they do not erase the inactive commit window.

Repo toolingcaution

The repository uses Composer build tooling, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, so their dependencies are not fixed to immutable revisions.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Grzegorz Byśkiniewicz

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^10.0 || ^11.0 || ^12.0 || ^13.0
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform