Package Health

dbp/relay-esign-bundle

Workflow actions are all unpinned, and the repository has no security policy or security-scanning tool. Licensing, tests, documentation, and organization backing provide useful transparency.

Latest v0.8.8PackagistPackagist

87%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-autoload-dump install lifecycle script runs during Composer installation, adding execution surface that should be understood before adoption.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected, leaving a modest gap in visible security hygiene.

Security policycaution

The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or write permissions, but all 6 action references are unpinned, weakening build reproducibility and action supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.1.4 || ^2.0.0 || ^3.0.0
league/uri
Version ^6.5 || ^7.0
symfony/uid
Version ^6.4 || ^7.4
symfony/config
Version ^6.4 || ^7.4
guzzlehttp/psr7
Version ^2.6 || ^3.0

Weekly Downloads

Info

Last Published
2 hours ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform