Package Health

esplora/lumos

It has a clear MIT license, repository tests, and release notes for this version. Install-time scripting and wholly unpinned workflow actions add avoidable supply-chain exposure, while the missing security policy reduces transparency.

Latest 1.1.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

A post-install-cmd script runs during installation, adding execution behavior beyond ordinary dependency resolution and increasing supply-chain exposure.

Release historycaution

The package has 9 releases over about 2 years, but none in the last 12 months; this is a meaningful maintenance concern despite a previously regular median interval of about 37 days.

Repo commit activitycaution

The repository recorded 0 commits from 0 active maintainers in the last 3 months, which supports the concern that active maintenance has slowed or stopped.

Security policycaution

No security policy was found, leaving vulnerability-reporting expectations unclear for a library that processes protected documents and archives.

Workflow auditcaution

All 10 analyzed action references are unpinned, which weakens build reproducibility. No untrusted checkout, script injection, dangerous trigger, or audit finding was reported, so this remains a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexandr Chernyaev

Direct Dependencies

DependencyLast ReleaseScore
symfony/mime
Version ^7.1
—
—
symfony/process
Version ^7.1
—
—
illuminate/support
Version ^11.0 || ^12.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform