Package Health

atoolo/runtime

Composer plugin for initializing bootstrapping logic such as initialization and requirement validation

Latest 1.3.0PackagistPackagist

88%

Total Score

healthy

Healthy release with recent maintenance, strong project hygiene, and only minor workflow pinning concerns.

Health Score Breakdown

Lifecycle scriptscaution

A post-install Composer script runs during installation, which adds execution complexity and deserves review, but this signal alone does not indicate abandonment or severe dependency risk.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting guidance undocumented. This is a transparency gap, not evidence that the release is unsafe.

Workflow auditcaution

All four workflows were analyzed without high- or medium-severity findings, and none use dangerous untrusted triggers or sinks. However, all three analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

veltrup

Direct Dependencies

DependencyLast ReleaseScore
symfony/dotenv
Version ^6.4.35 || ^7.4.7
—
—
symfony/filesystem
Version ^6.4.34 || ^7.4.6
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform