Package Health

asgrim/example-pie-extension

Tests, a clear README, and release notes improve day-to-day confidence. Maintenance still rests with one active contributor, while workflow pinning and security documentation are limited.

Latest 2.0.10PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

All recent commits came from one contributor, leaving maintenance dependent on a single person. The regular release history provides some evidence of continued attention but does not remove that concentration risk.

Repo commit activitycaution

There was one commit in the last 3 months, so the repository is still active, though the recent activity is sparse.

Repo toolingcaution

The project uses CMake and Composer, but no security-scanning tooling was detected. That is a modest transparency and maintenance weakness for a compiled extension.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting expectations undocumented.

Workflow auditcaution

All 17 analyzed action references are unpinned, and the audit found two high-confidence template-injection findings. No pull_request_target or workflow_run trigger and no untrusted checkout or script-injection sink were reported, so this is workflow hygiene risk rather than a severe standalone issue.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform