Package Health

fond-of-oryx/company-deleter-erp-delivery-note-connector

The repository remains active enough to be credible, with organization backing, tests, and a matching source tree. Workflow dependencies are unpinned and the project has no security policy, which weakens maintenance and release hygiene.

Latest 1.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is the package's only release, published about 3 years and 6 months ago, with no releases in the last 12 months. That is a meaningful sign of limited release maintenance, although the linked repository was pushed more recently.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months. Combined with the single registry release, this raises the risk that fixes or updates may arrive slowly.

Repo toolingcaution

The repository uses Make and Composer build tooling, which supports a reproducible project workflow. No security scanning tools were detected, leaving a modest hygiene gap.

Security policycaution

No security policy was found in the repository, so the process for reporting and handling vulnerabilities is not documented. This is a transparency weakness, but not evidence that the package is unsafe.

Workflow auditcaution

The workflow audit completed successfully and found no dangerous triggers or audit findings. All 3 action references are unpinned, however, which weakens build reproducibility and update integrity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Julian Hyatt

Direct Dependencies

DependencyLast ReleaseScore
fond-of-oryx/company-deleter
Version ^1.0.0
—
—
fond-of-oryx/erp-delivery-note
Version *
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform