Package Health

ibexa/ci-scripts

The repository remains active, with six recent commits from four contributors, organization backing, tests, security scanning, and a security policy. The release is old and all five workflow actions are unpinned; a high-confidence secrets-inherit finding adds workflow risk.

Latest v0.2.4PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Release historycaution

The latest registry release was published over two years ago, with no releases in the last 12 months, which lowers confidence in this specific version despite recent repository activity.

Workflow auditcaution

The audit covered both workflows, but all five action references are unpinned and a high-confidence medium-severity secrets-inherit finding exposes credentials more broadly than necessary. No untrusted checkout or script-injection paths were found, limiting the severity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^5.2
czproject/git-php
Version ^4.0.3
guzzlehttp/guzzle
Version ^6.5
knplabs/github-api
Version ^3.0
symfony/filesystem
Version ^5.0

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform