Package Health

arachne/codeception

The source repository has tests, release notes, an MIT license, and organization backing. Its workflow audit found all eight actions unpinned and a high-confidence secrets-inherit issue.

Latest v1.3.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package abandoned at package scope and names contributte/codeception as its replacement, making this release a poor default dependency choice.

Release historycaution

The package has 37 releases since 2014, but its latest registry release was about five years ago and there were no releases in the last 12 months. Recent repository activity partly offsets the staleness but not the release gap.

Repo bus factorcaution

All recent commits came from one contributor, leaving no demonstrated short-term contributor redundancy. Organization backing provides some handoff capacity but does not remove the concentration concern.

Repo commit activitycaution

Only one commit from one active maintainer was recorded in the last three months. That is some activity, but it indicates a very low current maintenance pace.

Workflow auditcaution

All 8 of 8 action references are unpinned, and the audit found a high-confidence medium-severity secrets-inherit issue in coverage.yml. No dangerous trigger or untrusted checkout was detected, but the workflow hygiene is weak.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jáchym Toušek

Direct Dependencies

DependencyLast ReleaseScore
nette/di
Version ^3.0
—
—
nette/http
Version ^3.0.3
—
—
nette/utils
Version ^3.0
—
—
nette/bootstrap
Version ^3.0
—
—
codeception/codeception
Version ^4.0.2
—
—

Weekly Downloads

Info

Last Published
5 years ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform