Package Health

hkyss/evocms-extras

The documentation and release notes are unusually complete for this young package. Its single-contributor maintenance base and fully unpinned workflow actions reduce confidence in long-term resilience.

Latest v1.6.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The package is only 17 days old, with four releases and a median interval of about 2 days. This shows active early development but provides little evidence of sustained maintenance.

Repo bus factorcaution

One contributor made 100% of the 40 recent commits. The repository is active, but this concentration creates a meaningful continuity risk for a package with a single publisher.

Workflow auditcaution

All 8 analyzed action references are unpinned, and one workflow grants top-level write permissions. No untrusted checkout, injection, or high-severity finding was reported, so this is workflow hygiene caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

hkyss

Direct Dependencies

DependencyLast ReleaseScore
illuminate/http
Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/view
Version ^8.0|^9.0|^10.0|^11.0|^12.0
guzzlehttp/guzzle
Version ^7.0
illuminate/console
Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/routing
Version ^8.0|^9.0|^10.0|^11.0|^12.0

Weekly Downloads

Info

Last Published
4 days ago
Created
22 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform