Package Health

cms-orbit/lms

The repository is actively changing, has two equally active contributors, and publishes release notes. It lacks security scanning and pins none of its three workflow actions, so maintenance controls remain a concern.

Latest 4.6.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-install command runs during installation, adding execution-time behavior beyond ordinary dependency loading. The provided signal does not show that it is unsafe, so this is a modest transparency concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This leaves an avoidable verification gap for a package handling installation and application code.

Security policycaution

The repository has no security policy, reducing transparency about how users should report vulnerabilities and receive fixes.

Workflow auditcaution

Both workflows were analyzed successfully and use read-only permissions with no detected dangerous sinks or audit findings. However, all three action references are unpinned, leaving workflow behavior exposed to upstream action changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
cms-orbit/core
Version ^4.6
laravel/framework
Version ^13.0

Weekly Downloads

Info

Last Published
2 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform