Package Health

amjadiqbal/vueforge-plugin

The package is licensed, documented, tested, and backed by a repository with release notes. Its security policy and automated security scanning are absent, while all four workflow actions are unpinned; the project is also too new to demonstrate sustained maintenance.

Latest v0.1.6PackagistPackagist

68%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

All six releases were published within about two hours, and the package is only 0 days old. This shows active initial work but provides no evidence of sustained maintenance yet.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools are configured. That leaves a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy. For a plugin handling backend integrations, this makes vulnerability reporting and response expectations unclear.

Version stabilitycaution

Version v0.1.6 is a non-stable 0.x release, so compatibility and maintenance maturity are not yet established. It is not marked as a prerelease, which partly reduces the concern.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Amjad Iqbal

Direct Dependencies

DependencyLast ReleaseScore
october/rain
Version >=4.2
composer/installers
Version ^1.0 || ^2.0

Weekly Downloads

Info

Last Published
1 day ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform