Package Health

yard/query-block

yard/query-block v2.0.0 appears generally healthy and suitable for dependency use: it has a stable release, regular release history, an active non-archived organization-owned repository, tests, licensing, dependency and build hygiene, and no install lifecycle scripts or dangerous workflow patterns. The main concerns are that recent repository work is concentrated in one contributor, repository popularity is very low, the repository lacks a security policy, and most workflows do not declare top-level token permissions. These are meaningful transparency and resilience gaps, but they do not outweigh the evidence of recent releases, ongoing repository activity, testing, and organizational backing.

Latest v2.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

One contributor accounts for all recent commits, creating a concentrated bus factor; organization ownership provides some capacity for handoff, but no second active contributor is shown.

Repo commit activitycaution

Only two commits from one active maintainer were recorded in the last three months, which shows recent activity but a thin maintenance base and potentially limited continuity.

Repo popularitycaution

The repository has only 2 stars and no forks, indicating limited external adoption or review; popularity is supporting evidence rather than a decisive health judgment, so this is a caution.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap for a dependency.

Token permissionscaution

Five of six workflows lack top-level permissions declarations and one workflow declares write access, reducing clarity around least-privilege automation despite the absence of other dangerous workflow patterns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
yard/data
Version ^2.0
—
—
jgrossi/corcel
Version ^9.0
—
—
illuminate/auth
Version ^12.0
—
—
webmozart/assert
Version ^1.11
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
28 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform