What Plumb checks

Every score is built from the checks below. Each one measures something observable about a package: its code, its configuration, its metadata, or its activity. Open a check to see exactly what it looks at, how it decides, and how to do well on the practice it measures.

Curious how the checks combine into a score? Read how scoring works.

Security

How likely the package is to become a way in for an attacker, or to expose its users to a known vulnerability.

Maintenance

How likely the package is to be patched and supported over time.

Ecosystem

Whether the package keeps up with the PHP, Laravel, and Symfony releases its users run.