yard/query-block v2.0.0 appears generally healthy and suitable for dependency use: it has a stable release, regular release history, an active non-archived organization-owned repository, tests, licensing, dependency and build hygiene, and no install lifecycle scripts or dangerous workflow patterns. The main concerns are that recent repository work is concentrated in one contributor, repository popularity is very low, the repository lacks a security policy, and most workflows do not declare top-level token permissions. These are meaningful transparency and resilience gaps, but they do not outweigh the evidence of recent releases, ongoing repository activity, testing, and organizational backing.
78%
Total Score
75
100
94
80
One contributor accounts for all recent commits, creating a concentrated bus factor; organization ownership provides some capacity for handoff, but no second active contributor is shown.
Only two commits from one active maintainer were recorded in the last three months, which shows recent activity but a thin maintenance base and potentially limited continuity.
The repository has only 2 stars and no forks, indicating limited external adoption or review; popularity is supporting evidence rather than a decisive health judgment, so this is a caution.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap for a dependency.
Five of six workflows lack top-level permissions declarations and one workflow declares write access, reducing clarity around least-privilege automation despite the absence of other dangerous workflow patterns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yard/data Version ^2.0 | — | — |
jgrossi/corcel Version ^9.0 | — | — |
illuminate/auth Version ^12.0 | — | — |
webmozart/assert Version ^1.11 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.