Package Health

greenter/ubl-validator

This is a generally healthy package to depend on: it has a stable MIT-licensed release, a correctly matching organizational repository, comprehensive repository tests, a non-archived source repository, and a release published very recently. The main concerns are modest maintenance velocity—only one release in the last 12 months and no commits or active maintainers in the last 3 months—and incomplete repository security hygiene, including no security policy and no explicit workflow token permissions. These issues warrant monitoring but do not currently indicate abandonment or an unfit dependency.

Latest v2.3.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a limited publishing base. However, the repository is owned by an organization, so the short registry maintainer list is not by itself strong evidence of weak project backing.

Release historycaution

The package has existed for 3141 days with 8 releases and a latest release on the assessment date, but only 1 release in the last 12 months. The recent release is reassuring, while the low annual release cadence suggests maintenance is steady but not highly active.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last 3 months, which is a meaningful indication of currently low maintenance velocity. This is partly offset by the very recent release and repository push, but the release may not reflect sustained ongoing development.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. The absence of automated security scanning is a repository hygiene gap, though it does not alone make the package unfit.

Security policycaution

The repository has no security policy. This reduces transparency about vulnerability reporting and response procedures, although it is a documentation gap rather than evidence of abandonment.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Giancarlos Salas

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
19 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform