Package Health

bnussbau/trmnl-pipeline-php

Regular releases, tests, a changelog, and a matching MIT license support ongoing use. Maintenance is concentrated in one contributor, so ownership continuity remains a concern.

Latest 1.1.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The repository is owned by the same individual account that publishes the package, so the single-person maintenance concentration is not offset by organization backing.

Repo bus factorcaution

One contributor made all recent commits, leaving maintenance dependent on a single active person and increasing continuity risk.

Repo commit activitycaution

Only two commits were recorded in the last three months, so current maintenance activity is modest despite the recent release.

Workflow auditcaution

The audit found a high-confidence, high-severity bot-condition issue in the Dependabot auto-merge workflow. All nine action references are unpinned, and a test workflow installs a package outside its lockfile, adding workflow supply-chain hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

bnussbau

Direct Dependencies

DependencyLast ReleaseScore
league/pipeline
Version ^1.0
—
—
spatie/browsershot
Version ^5.0
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform