Package Health

hks-systeme/php-cs-fixer-config

The project has clear documentation, tests, release notes, and automated dependency and static-analysis tooling. Its published release line is stale, while workflow references are entirely unpinned and the audit found a high-severity bot-condition issue.

Latest 2.9.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was published about four and a half years ago, with no releases in the last 12 months. Recent repository activity partly offsets the stale package cadence, but consumers would be relying on an old release line.

Repo commit activitycaution

There were no commits and no active maintainers in the three months measured. This weakens evidence of ongoing maintenance, although recent pull-request activity and a recent push provide some contrary evidence.

Security policycaution

No repository security policy was found. This is a transparency gap, though it is less significant for a small developer tooling configuration package than for security-sensitive software.

Workflow auditcaution

All 41 analyzed action references are unpinned, which weakens build reproducibility. The audit also found a medium-confidence, high-severity bot-condition issue in merge.yaml; the pull_request_target and workflow_run triggers had no untrusted checkout or script-injection sinks, so this is a meaningful hygiene risk rather than an automatic release blocker.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Andreas Möller

Direct Dependencies

DependencyLast ReleaseScore
friendsofphp/php-cs-fixer
Version ~3.6.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform