Package Health

cu-boulder/ucb_d9_custom_entities

University of Colorado Boulder custom entities

Latest 20261007PackagistPackagist

70%

Total Score

caution

Active releases and organizational backing offset a license mismatch and weak GitHub Actions pinning.

Health Score Breakdown

Licensecaution

The artifact declares MIT but its LICENSE file was detected as GPL-2.0, creating a material licensing ambiguity despite a license file being present.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent even though the repository content appears related to custom entities.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, which makes vulnerability reporting and response expectations less clear.

Workflow auditcaution

All five workflows were analyzed without untrusted checkouts or script injection, but all five uses are unpinned and one high-confidence medium-severity finding shows secrets inherited by a reusable workflow. Missing top-level permissions blocks are acceptable on their own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 day ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform