Package Health

bedita/dev-tools

Security-policy coverage is absent, and every workflow action reference is unpinned. The package is licensed, tested, actively released, and backed by an organization, which offsets those maintenance and hygiene concerns.

Latest v3.2.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

The repository recorded no commits and no active maintainers during the last three months. This is a meaningful maintenance warning, although the recent package release and repository push provide some counterevidence.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.

Workflow auditcaution

All 10 analyzed action references are unpinned, weakening build reproducibility and increasing exposure to upstream action changes. The pull_request_target workflow has no untrusted checkout or script-injection finding, and missing top-level permissions are acceptable on their own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chia Lab s.r.l.
ChannelWeb s.r.l.

Direct Dependencies

DependencyLast ReleaseScore
cakephp/cakephp
Version ^5.2
—
—
cakephp/debug_kit
Version ^5.2
—
—

Weekly Downloads

Info

Last Published
7 months ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform