Package Health

dniccum/secret-stash-cli

The package has a clear README, repository tests, release notes, and an MIT license. Maintenance is concentrated in one contributor, while workflow permissions and action pinning need tightening.

Latest v1.1.0PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo bus factorcaution

One contributor made 100% of the two recent commits, and the project is user-owned rather than organization-owned, leaving limited demonstrated handoff capacity.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months, with one active maintainer. Recent merged pull requests show some activity, but direct commit activity is thin.

Security policycaution

The repository has no security policy. For a package that manages environment variables and authentication, this is a meaningful transparency gap.

Workflow auditcaution

All 14 analyzed action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, which limits the risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Doug Niccum

Direct Dependencies

DependencyLast ReleaseScore
nesbot/carbon
Version ^3.11
—
—
endroid/qr-code
Version ^5.0.9
—
—
illuminate/http
Version ^11.0|^12.0|^13.0
—
—
laravel/prompts
Version ^0.3.0
—
—
guzzlehttp/guzzle
Version ^7.10|^8.2
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform