Package Health

beechit/default-upload-folder

The repository has had no commits in three months, and its only workflow uses two unpinned actions. A recent stable release, active organization backing, and clear README help, but the workflow audit found a high-confidence template-injection pattern.

Latest 3.0.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The project has existed for about 9 years with 19 releases, but only one release in the last 12 months. The latest release is recent, so this indicates slowing activity rather than abandonment.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance concern, although the recent release and push provide some compensating evidence.

Repo toolingcaution

Composer is used for the build, but no security-scanning tools are configured. The missing scanning is a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.

Workflow auditcaution

The only workflow uses two unpinned actions and contains a high-confidence template-injection finding. There are no untrusted checkouts or write-wide permissions, so this is a hygiene concern rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4

Weekly Downloads

Info

Last Published
10 months ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform