Package Health

extport/protobuf

The mirror has active automated releases, tests, and a changelog, with organization backing. One maintainer owns all five recent commits, while broad workflow write permissions and template-injection findings reduce confidence in its automation hygiene.

Latest 36.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made all five recent commits, creating a genuine continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced.

Repo toolingcaution

Composer is used for builds, but no repository security-scanning tool was detected. For an automated binary mirror, this is a modest transparency and hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no security policy, leaving reporting and response expectations undocumented for a package that distributes extension source and binaries.

Workflow auditcaution

All four workflows were analyzed and all 12 action references are pinned, with no untrusted checkouts or script-injection findings. However, three workflows grant top-level write permissions and the build workflow has high- and medium-confidence template-injection findings; without an untrusted trigger these are workflow-hygiene concerns, not a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform