Package Health

brunoconte3/dev-utils

This release appears healthy and suitable for dependency use: it has a long release history with frequent recent releases, a stable non-prerelease version, no registry deprecation, an active and non-archived repository, reproducible-looking Composer scaffolding, repository tests and CI workflows, and a balanced two-person recent contributor base. The main reservations are the absence of a repository security policy and explicit GitHub Actions token permissions, plus no configured security-scanning tool; these are security-hygiene gaps rather than evidence of abandonment. The package artifact omits tests and a changelog, but repository tests and CI materially compensate for those omissions.

Latest 3.1.1PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Project backingcaution

The repository is owned by a named user rather than an organization, so the project has individual-owner backing. Recent activity from two contributors partially offsets the resulting continuity risk.

Repo toolingcaution

Composer build tooling and repository quality configurations are present, but no security-scanning tool was detected. The missing security automation is a genuine hygiene gap, though it does not by itself indicate unsafe maintenance.

Security policycaution

The repository has no security policy. This weakens vulnerability-reporting transparency and response expectations, although it is not evidence that the package is abandoned.

Token permissionscaution

All three workflows lack top-level token permission declarations. Even though none declares top-level write access, explicitly limiting permissions would provide stronger CI security hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bruno Conte
Walter de Padua Junior
Jonathan Bersot Augusto
Robson Willian da Silva
Rafael Henrique Barbosa Pereira
Rafael Gomes de Souza
Adalberto Silveira Nápoles
Antonio Cruz
Caio Brioli
Willian Joaquim Barros Lúcio
Eliseu Lorena Vidal
Guilherme Henrique Ribeiro
Wellington Valentin Salatta
Erick Hiroki Abe / 阿部広紀
Thales Santos
Luca Mattosinho Teixeira

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
22 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform