Package Health

hasnrizvee/dep-reaper

The README, tests, and release notes make the tool easier to evaluate, while read-only workflow permissions limit CI exposure. Missing security scanning and unpinned Actions leave avoidable maintenance and build-integrity gaps.

Latest v1.0.0PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This package has only one release, published about 179 days ago, so there is little evidence of an established release or maintenance pattern.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance for a recently published tool.

Repo toolingcaution

Composer and Box provide build tooling, but the repository reports no security-scanning tools, leaving a meaningful transparency and maintenance gap.

Security policycaution

No security policy is present, so users have no documented vulnerability-reporting path or stated security response process.

Workflow auditcaution

All 2 analyzed action references are unpinned, creating avoidable build-integrity risk. The workflow uses read-only permissions and has no untrusted checkout or script-injection findings, which limits the exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hasan Rizvee

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^6.0|^7.0
—
—
nikic/php-parser
Version ^5.0
—
—
phpstan/phpdoc-parser
Version ^1.0
—
—
symfony/dependency-injection
Version ^6.0|^7.0
—
—
composer-unused/symbol-parser
Version ^0.2
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform