Package Health

zorca/roles-and-permissions

Risky to adopt without accepting maintenance risk: the package has had no release or commit activity since early 2022. It remains licensed, documented, tested in the repository, and not deprecated, but its long-term abandonment risk is substantial.

Latest 1.1.2PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

The package has made 4 releases, but none in the last 12 months; its latest registry release was January 24, 2022, roughly 4 years and 8 months before collection. This long release gap is a strong maintenance concern.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the release history showing no releases since January 2022. The repository is not archived, but there is no observed recent development to offset the inactivity.

Dangerous workflowscaution

One workflow uses pull_request_target, which can be sensitive because it runs with the base repository context, but no untrusted checkout or script-injection patterns were detected. The workflow design warrants review rather than indicating a severe package-health failure.

Maintainerscaution

Only one registry account has publish access, and the project is backed by an individual account rather than an organization. This matters more because the repository also shows prolonged inactivity, increasing single-maintainer abandonment risk.

Repository archivedcaution

The repository is not marked archived, which preserves a path for future maintenance, but its last push was May 25, 2022 and the current activity indicators show no recent work. This is cautionary rather than an archived-repository verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

ajimoti

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^8.73
—
—
bensampo/laravel-enum
Version ^4.1
—
—
spatie/laravel-package-tools
Version ^1.9.2
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform