Package Health

cerpus/questionbank-client

The release is licensed and includes tests, a changelog, and release notes. Its workflow uses four unpinned actions, while security scanning and a security policy are absent.

Latest v2.4.0PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package has 34 releases over about 8 years, but its latest release was in December 2024 and there were no releases in the following 12 months, which lowers confidence in active maintenance.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months. The repository was pushed in February 2025, so this indicates a recent maintenance pause rather than confirmed abandonment.

Repo toolingcaution

Composer is used for the build, but no security scanning tools are configured. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.

Security policycaution

The repository has no security policy. For a service client that handles authentication configuration, this leaves vulnerability-reporting expectations unclear.

Workflow auditcaution

All four analyzed action references are unpinned, reducing build reproducibility. The audit also reported a low-confidence cache-poisoning pattern; because confidence is low and no untrusted trigger or checkout was found, it is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thomas Horn Sivertsen
Odd-Arne Johansen

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0
—
—
illuminate/support
Version ^9.0|^10.0|^11.0
—
—
cerpus/cerpushelper
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform