Package Health

happytodev/blogr-gdpr

Clear documentation, tests, release notes, and an MIT license improve confidence. The repository is young and single-maintainer, while all four workflow actions are unpinned; adoption is reasonable with those maintenance and build-hygiene limits.

Latest 2.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo bus factorcaution

One contributor made all 8 commits in the last 3 months, giving the project a bus factor of one. The repository is user-owned rather than organization-owned, so there is no provided backing evidence to offset that concentration.

Repo commit activitycaution

The repository recorded 8 commits in the last 3 months, showing ongoing work. However, all activity is concentrated in one active maintainer, limiting resilience if that person stops maintaining it.

Repo toolingcaution

Composer is used for builds, but no security-scanning tool was detected. This is a modest transparency gap for a plugin handling consent and personal-data workflows, not evidence of unsafe code.

Security policycaution

The repository has no security policy. For a GDPR-focused plugin that processes consent and data requests, the missing disclosure path modestly reduces maintenance and vulnerability-reporting transparency.

Workflow auditcaution

Both workflows were fully analyzed with no injection, untrusted-checkout, or audit findings, and they do not grant top-level write access. However, all 4 of 4 action references are unpinned, leaving build inputs less reproducible and increasing supply-chain hygiene risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

HappyToDev

Direct Dependencies

DependencyLast ReleaseScore
happytodev/blogr
Version *
filament/filament
Version ^5.0
laravel/framework
Version ^13.0

Weekly Downloads

Info

Last Published
2 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform