Package Health

blueways/bw-icons

A clear README, repository tests, and a proper license make integration and ongoing use easier. Ownership is concentrated in one contributor, while workflow permissions and security-policy coverage are limited.

Latest 4.3.2PackagistPackagist

76%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

60

Health Score Breakdown

Dangerous workflowscaution

One of four workflows uses pull_request_target, which can require careful privilege handling even though no untrusted checkout or script-injection pattern was detected.

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script, adding execution during dependency installation and therefore a modest supply-chain hygiene concern.

Maintainerscaution

Only one account has registry publish access. That is a limitation, but the repository's recent activity shows the package is currently being maintained.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.

Repo bus factorcaution

One contributor made all seven recorded contributor commits in the recent period, so maintenance could be disrupted if that person becomes unavailable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Maik Schneider

Direct Dependencies

DependencyLast ReleaseScore
typo3/cms-core
Version ^12.4 || ^13.4
phenx/php-font-lib
Version ^1.0
sabberworm/php-css-parser
Version ^8.4.0

Weekly Downloads

Info

Last Published
5 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform