Package Health

citation-style-language/styles

The organization provides a clear README, release notes, build tooling, and automated dependency scanning. GitHub Actions use read-only permissions, but all 19 actions are unpinned and one pull-request workflow combines untrusted checkout with a cache-poisoning finding.

Latest v0.2.221PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Security policycaution

The repository has no security policy, which leaves vulnerability reporting and response expectations less transparent. This is a modest maintenance and transparency gap in an otherwise active project.

Workflow auditcaution

All four workflows were analyzed and use read-only permissions, but all 19 action references are unpinned. One pull-request-target workflow checks out untrusted content, and the auditor reported a low-confidence cache-poisoning pattern; these warrant workflow hygiene caution without outweighing the project's maintenance evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Citation Style Language (CSL) Team

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform