Package Health

cocoon-projet/config

Clear documentation, tests, and licensing support adoption. The focused dependency set and read-only workflow permissions help, but the project shows limited recent maintenance and weak build-security hygiene.

Latest 0.4.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package has only 4 releases since April 2018, with no releases in the last 12 months and a median interval of about 537 days. The latest release is recent enough to avoid an abandonment verdict, but the cadence is slow.

Repo commit activitycaution

The repository had 0 commits and 0 active maintainers in the last 3 months. Combined with the absence of releases in the last 12 months, this indicates limited recent maintenance.

Repo toolingcaution

Composer is used for the build, but no security-scanning tooling was detected. This is a modest transparency and hygiene gap rather than evidence that the package is unsafe.

Workflow auditcaution

The single workflow was fully analyzed and uses read-only permissions, with no untrusted checkouts or injection findings. However, all 4 action references are unpinned, leaving avoidable dependency-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Cocoon Projet

Direct Dependencies

DependencyLast ReleaseScore
tracy/tracy
Version ^2.10
symfony/finder
Version ^3.4
vlucas/phpdotenv
Version ^5.6

Weekly Downloads

Info

Last Published
1 year ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform