Package Health

chstudio/raven

Clear documentation, tests, release notes, and organization-backed ownership provide useful maintenance context. Recent repository inactivity, no security policy, and unpinned workflow actions leave meaningful gaps in ongoing care and build hygiene.

Latest v0.6.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. A recent push and release provide some compensation, but this still weakens confidence in ongoing maintenance.

Repo issue activitycaution

There were no new or closed issues and no merged pull requests in the last month, so current project interaction appears limited.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Version stabilitycaution

Version v0.6.0 is not a stable major release, but it is not marked as a prerelease and recent releases contain documented changes.

Workflow auditcaution

The audit covered both workflows with no high-confidence findings or unsafe triggers, but all 13 action references are unpinned and neither workflow has a top-level permissions block, creating build reproducibility and token-scoping concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Stéphane Hulard

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0|^2.0|^3.0
—
—
fakerphp/faker
Version ^1.20
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.0
—
—
psr/http-message
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform