Package Health

bedita/i18n-google

Testing, release notes, and organization backing provide useful maintenance context. The MIT declaration conflicts with the included LGPL-3.0 license, while no commits were recorded in the last three months. All workflow actions are unpinned and the repository has no security policy.

Latest v2.0.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensecaution

The manifest declares MIT, but the artifact and repository license file is LGPL-3.0. This mismatch creates a real licensing concern despite the presence of a license file.

Repo commit activitycaution

No commits or active maintainers were recorded during the last three months. The recent release provides some compensating evidence, but the current maintenance signal is weak.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

Both workflows were analyzed without audit findings, and the pull_request_target trigger has no untrusted checkout or script-injection sink. However, all 10 action references are unpinned, which weakens build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
bedita/i18n
Version ^6.0.0
—
—
cakephp/utility
Version ^5.0
—
—
google/cloud-translate
Version ^1.15
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform