Package Health

feedbox-cz/xml-manipulate

The repository is tiny and has no recent commits, while all five workflow actions are unpinned. It is not deprecated or archived, and repository tests plus an MIT declaration provide limited reassurance.

Latest v0.0.1-RC1PackagistPackagist

43%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This is the package's only release, published over five years ago, with no releases in the last 12 months; that strongly indicates abandonment risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected; this is a modest transparency and maintenance gap for a package with otherwise limited activity.

Version stabilitycaution

The latest and only release is v0.0.1-RC1, still a prerelease after more than five years, so the API and maintenance status are immature.

Workflow auditcaution

The single workflow was fully analyzed with no injection or high-severity findings, but all five action references are unpinned, leaving avoidable build-integrity risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Filip Šedivý

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform