84
/ 100
Well engineered. The main gaps are a reproducible setup and a contributing guide.
Security-focused Laravel static analyser
Top fixes
Highest-impact changes first, ranked by point weight
- 1Tests18pt
Wire your tests to a documented command (e.g. a test script in your build config) so the suite is reproducible.
- 2Install and run instructions9pt
Add a .env.example listing all required environment variables so contributors know what to set up.
- 3Reproducibility6pt
Commit composer.lock so Composer installs are repeatable.
- 4Reproducibility6pt
Add a Dockerfile, .nvmrc, or .python-version to pin the runtime version and make the environment reproducible.
Working through the fixes? Let every push regrade itself.
The free GitHub App rescans this repo on every push and posts the grade as a commit check, so the score climbs without coming back to rescan by hand.
Scorecard
Every check, grouped by category and sorted worst-first
Documentation
90
CONTRIBUTING guide is very brief (−12 pts for depth). 150+ words earns +6 pts; 400+ earns +12 pts.
→ Add setup instructions, code style notes, and how to run tests.
README documents how to install the project.
README is present.
Licensed under MIT.
Engineering
82
No dependency lockfile found (−70 pts).
→ Commit composer.lock so Composer installs are repeatable.
Test files detected (phpunit.xml.dist).
CI is configured (.github/workflows/lint-workflows.yml).
PHP linting configured (.editorconfig).
Issue or PR templates present.
Project health
100
Dependency manifest found (composer.json).
Repository has a description.
Actively maintained (pushed within the last month).
.gitignore present.
Repository health signals
Activity, community, and responsiveness at scan time
Activity
- 122 / 444Commits (30d / 90d)
- 79Forks
- 169Releaseslatest 7y ago
Community
- 75% - GoodCommunity health
- -authors own >50% of commits
- 335Watchers
Responsiveness
- 2d 6hMedian issue response
- 14hMedian PR merge time
- 2Open issues
Repository files22 root entries
- .githubGood: CI is configured (.github/workflows/lint-workflows.yml).Good: Dependabot configured for github-actions.Good: Issue or PR templates present.
- bin
- docs
- resources
- src
- stubs
- tests
- tools
- _typos.toml
- .editorconfigGood: PHP linting configured (.editorconfig).
- .gitattributes
- .gitignoreGood: .gitignore present.
- .php-cs-fixer.php
- composer.jsonGood: Dependency manifest found (composer.json).
- CONTRIBUTING.mdIssue: CONTRIBUTING guide is very brief (−12 pts for depth). 150+ words earns +6 pts; 400+ earns +12 pts.Fix: Add setup instructions, code style notes, and how to run tests.Issue: Contributing guide lacks a setup section (−12 pts).Fix: Show new contributors how to get a local dev environment running.Issue: Contributing guide lacks a code style section (−8 pts).Fix: Describe your linting/formatting rules and how to run them.Issue: Contributing guide lacks a testing section (−8 pts).Fix: Show contributors how to run the test suite (e.g. npm test, pytest, cargo test).Issue: Contributing guide lacks a PR workflow section (−8 pts).Fix: Explain how to fork, branch, and open a pull request so contributors know what to expect.Good: Contributing guide includes code examples.
- LICENSEGood: Licensed under MIT.
- phpunit.xml.distGood: Test files detected (phpunit.xml.dist).
- psalm.xml
- README.mdGood: README is present.Good: README is well structured with multiple sections.Good: README includes screenshots or visuals. Great for first impressions.Good: README has code examples.Good: README links to a live demo or deployed app.Good: README includes status badges.Good: README documents how to install the project.Good: README documents how to run the project.
- rector.php
- SECURITY.mdGood: Security policy present.
- UPGRADING.md
Add this badge to your README
It updates automatically each time the repo is re-graded.
[](https://www.repo-grade.com/report/psalm/psalm-plugin-laravel)