Package Health

answear/inpost-pickup-point-bundle

Tests, release notes, and organizational ownership improve confidence. The repository shows no commits in the last three months, while all six workflow actions are unpinned and no security policy or scanning is present.

Latest 4.2.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package uses post-install and post-update Composer scripts. These add installation complexity and warrant caution even though no separate evidence shows harmful behavior.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance warning, although the recent release shows that the project has not been abandoned outright.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. That reduces automated assurance around dependency and repository security hygiene.

Security policycaution

The repository has no security policy. This weakens transparency about vulnerability reporting and response expectations.

Workflow auditcaution

Both workflows were fully analyzed with no high-confidence audit findings or dangerous triggers, but all six action references are unpinned. Missing top-level permissions blocks are acceptable here because no workflow has top-level write access, while unpinned actions remain a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^2.6
—
—
webmozart/assert
Version ^1.11|^2.0
—
—
guzzlehttp/guzzle
Version ^7.8.2
—
—
symfony/serializer
Version ^7.0.3|^8.0
—
—
guzzlehttp/promises
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform