Package Health

adamjenkins/moodle-block_oerexchangebrowse

The package is licensed, documented, and backed by repository tests with recent development activity. Its limited security process leaves less evidence for handling problems as the project grows.

Latest v1.0.3PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is young at 59 days and has six releases, with the latest releases arriving within roughly 3 hours of one another during the initial publishing period. This shows active early iteration but provides little long-term maintenance history.

Repo bus factorcaution

All 17 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single person. The repository is user-owned rather than organization-backed, so there is no provided evidence of an internal handoff path.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response expectations. This is a process gap, not evidence that the package is unsafe.

Workflow auditcaution

The audit found three high-confidence template-injection findings in the release workflow, plus all 6 action references are unpinned and one workflow grants top-level write access. No untrusted checkout or script-injection path was found, so this is a meaningful hygiene concern rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adam Jenkins

Direct Dependencies

DependencyLast ReleaseScore
moodle/moodle
Version >=5.0 <5.3
—
—
moodle/composer-installer
Version ^1.0
—
—
adamjenkins/moodle-local_oerexchange
Version *
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform