Package Health

digitoimistodude/dude-coding-standards

Usable with caveats: it is actively released, clearly licensed, tested, and backed by an organization. The main concerns are that all recent commits come from one contributor, the README calls the standard a work in progress for internal use, and the repository lacks a security policy and explicit top-level workflow permissions.

Latest 1.0.11PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

The package includes a substantial README, tests, a changelog, and release notes for version 1.0.11. The README also transparently describes the standard as a work in progress and primarily used by the owning organization, which limits confidence for external consumers.

Repo bus factorcaution

All five recent commits came from one contributor, creating a real continuity risk. Organization backing provides some ability to hand off maintenance, but no second active contributor is shown.

Repo toolingcaution

Composer is used for builds, but no security-scanning tool was detected. This is a transparency and assurance gap, though it is not by itself evidence of an unsafe package.

Security policycaution

The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting and response expectations unclear.

Token permissionscaution

Neither workflow declares top-level token permissions, and only one has job-level permissions. Explicit least-privilege permissions would provide stronger protection for the release automation.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Digitoimisto Dude Oy

Direct Dependencies

DependencyLast ReleaseScore
wp-coding-standards/wpcs
Version ^3.0
—
—
phpcsstandards/phpcsextra
Version ^1.2.0
—
—
phpcsstandards/phpcsutils
Version ^1.0
—
—
squizlabs/php_codesniffer
Version ^3.13
—
—
phpcompatibility/php-compatibility
Version ^9.3
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform