Package Health

custom-d/word-finder

The README still contains placeholder text, and all four workflow actions are unpinned. Tests, release notes, an MIT license, and an unarchived repository provide useful transparency, but do not offset the maintenance risk.

Latest v1.2.4PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The last release was on September 8, 2021, and there were no releases in the following five years. This is strong evidence that maintenance has stopped.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers during the last three months of collection, consistent with the long release hiatus.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. That modestly reduces supply-chain transparency without proving the release is unsafe.

Security policycaution

The repository has no security policy, leaving no documented reporting process. This is a transparency gap, though it is secondary to the package’s lack of recent maintenance.

Workflow auditcaution

All four analyzed action references are unpinned, weakening build reproducibility and exposing workflow dependencies to change. The audit found no untrusted checkouts, script injection, or high-severity issues.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Craig Smith

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^7.0|^8.0

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform