Package Health

bartlett/captainhook-bin-plugin

Captain Hook Plugin to execute any binary dependencies if (and only if) packages are installed

Latest 1.1.0PackagistPackagist

65%

Total Score

caution

Usable with caveats: maintenance has gone quiet, and release workflows have weak supply-chain hygiene.

Health Score Breakdown

Project backingcaution

The repository is owned by an individual rather than an organization, so there is no demonstrated organizational maintenance backup for the single registry maintainer.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance after the recent release.

Repo toolingcaution

Composer and Box provide build tooling, but no security-scanning tool was detected, leaving a transparency and review gap.

Security policycaution

The repository has no security policy, so users are given no documented reporting or response process.

Workflow auditcaution

All 16 action references are unpinned, and the release workflow has a high-confidence template-injection finding; the low-confidence cache-poisoning finding is only a hygiene concern, but together the workflow controls are weaker than desirable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Laurent Laville

Direct Dependencies

DependencyLast ReleaseScore
composer/semver
Version ^3.0
—
—
captainhook/captainhook
Version ^5.28.4
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform