Package Health

cloudcreativity/ddd-modules

The organization-backed project has repository tests, release notes, a clear license, and no install-time scripts. Its small dependency set and documented package structure are reassuring, but security scanning is absent.

Latest v6.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is concerning after otherwise regular releases, though the recent release and June push partly offset the abandonment risk.

Repo issue activitycaution

There has been no issue or pull-request activity in the last month, with one open issue. This is a modest maintenance concern but not strong evidence of abandonment by itself.

Repo toolingcaution

Composer is used for the build, but no security scanning tools were detected. That leaves a meaningful transparency and detection gap for a dependency intended for application use.

Security policycaution

The repository has no security policy. This weakens disclosure transparency and contributor guidance, although it is not evidence that the release is unsafe.

Workflow auditcaution

Both workflows were analyzed successfully and had no auditor findings, with one workflow using read-only permissions. However, all 8 action references are unpinned and one workflow has top-level write permissions, creating avoidable workflow supply-chain and privilege hygiene gaps.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cloud Creativity Ltd
Christopher Gammie

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^2.0 || ^3.0
ramsey/uuid
Version ^4.7
psr/container
Version ^2.0
symfony/polyfill-php85
Version ^1.33

Weekly Downloads

Info

Last Published
3 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform