Package Health

cpsit/project-builder

Regular releases, a current repository, clear licensing, and documented usage support dependable adoption. Single-contributor recent activity and no security policy add upkeep uncertainty; workflow concerns should be corrected before trusting release automation.

Latest 3.0.3PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made all recent commits, concentrating current project knowledge and increasing handoff risk; organization backing provides some compensation but does not remove the concentration.

Repo commit activitycaution

The repository recorded 8 commits in the last 3 months, but all came from one active maintainer, leaving limited recent maintenance capacity.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.

Workflow auditcaution

All 28 analyzed action references are pinned and no untrusted checkout or injection sink was detected, but two high-confidence template-injection findings and one workflow with top-level write permissions weaken release-workflow hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Elias Häußler
Martin Adler

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.3.3
nyholm/psr7
Version ^1.5
cuyz/valinor
Version ^2.2
symfony/yaml
Version ^5.4 || ^6.4 || ^7.4 || ^8.0
cocur/slugify
Version ^4.1

Weekly Downloads

Info

Last Published
28 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform