Package Health

bitbag/blacklist-plugin

Tests, a substantial README, and organization backing provide useful context. There is no security policy, and all 12 workflow actions are unpinned, so maintenance and build hygiene deserve attention.

Latest v3.0.1PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 17 releases since June 2021, but none in the last 12 months; the latest release was in July 2025. This indicates a meaningful maintenance slowdown.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. That weakens evidence of ongoing maintenance, although the repository is not archived and had a recent release.

Security policycaution

The linked repository has no security policy. For a plugin handling checkout and fraud-prevention behavior, this is a transparency gap.

Workflow auditcaution

All 12 analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning findings are low-confidence hygiene warnings and do not independently establish a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
dompdf/dompdf
Version ^2.0
—
—
sylius/sylius
Version ~2.0.0
—
—
symfony/workflow
Version ^7.2
—
—
symfony/webpack-encore-bundle
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform