Package Health

coldtrick/static

The package includes a usable README, changelog, release notes, and a clear source tree. Its organization-backed team is small, so continuity depends on two active contributors, while workflow action pinning and a missing security policy leave modest process gaps.

Latest v15.0.3PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo toolingcaution

Composer is used as the build tool, but no security scanning tool was detected. The missing scanning layer is a modest transparency and maintenance-process gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a process gap rather than evidence of unsafe code.

Workflow auditcaution

All 3 workflows were analyzed cleanly with no untrusted checkouts, injection findings, or risky audit findings. However, all 3 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
3 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform