Package Health

ameax/datev-xml

Tests, a changelog, recent releases, and organizational ownership provide useful maintenance evidence. The missing security policy and workflow hygiene issues leave less transparency and automation safety than a mature project should have.

Latest 2.1.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. Although releases occurred during the last year, this recent lack of source activity is a maintenance caution.

Security policycaution

No security policy is present in the repository. This is a transparency gap, though it is not evidence that the package is unsafe by itself.

Workflow auditcaution

All 9 analyzed action references are unpinned, and three workflows grant top-level write permissions; the audit also found one high-confidence bot-condition issue. The pull_request_target workflow has no untrusted checkout or script-injection finding, limiting the severity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Michael Schmidt

Direct Dependencies

DependencyLast ReleaseScore
sabre/xml
Version ^4.0
—
—
nesbot/carbon
Version ^2.0|^3.0
—
—
ameax/xml-validator
Version ^1.0
—
—
spatie/temporary-directory
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform