Package Health

datamweb/codeigniter-dea-rule

The repository is licensed, tested, documented, and not archived. Its workflows use unpinned actions and include a high-confidence unpinned container image; the update hook also adds some execution risk.

Latest v0.0.1PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

This is the only release, published nearly three years ago, with no releases in the last 12 months. That substantially raises abandonment risk despite the repository remaining available.

Lifecycle scriptscaution

The package declares a post-update command, which introduces code execution during dependency updates. No other provided signal shows that this hook is unsafe, so the concern is limited.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. This is consistent with the old release history and suggests limited ongoing maintenance.

Version stabilitycaution

Version v0.0.1 is an early, pre-1.0 release, so compatibility and project maturity are less established than for a stable-major package.

Workflow auditcaution

All 32 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in the PHPUnit workflow. The workflows have no untrusted checkout or script-injection findings, which limits the overall impact.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pooya Parsa Dadashi

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform