Package Health

idmarinas/composer-plugin

The package is clearly licensed, documented, and tied to a matching source repository with release notes. Its workflows use unpinned actions, one audit file failed, and the recent maintenance record is quiet; these warrant checking before adoption.

Latest 1.5.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

Only one release was published in the last 12 months, despite a much shorter historical median release interval, indicating a substantial slowdown in delivery.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, which is a clear recent-maintenance concern.

Repo popularitycaution

The repository has zero stars and forks and one watcher, indicating limited external adoption; this is supporting caution rather than a verdict by itself.

Security policycaution

No repository security policy was found, reducing transparency for reporting and handling vulnerabilities, although this is a secondary concern for the score.

Workflow auditcaution

Both workflow action references are unpinned, and one workflow file failed the audit, so the result is incomplete and reproducibility is weaker. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not dangerous on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Iván Diaz Marinas (IDMarinas)

Direct Dependencies

DependencyLast ReleaseScore
symfony/lock
Version ^6.4 | ^7.0 | ^8.0
—
—
symfony/finder
Version ^6.4 | ^7.0 | ^8.0
—
—
symfony/string
Version ^6.4 | ^7.0 | ^8.0
—
—
symfony/validator
Version ^6.4 | ^7.0 | ^8.0
—
—
symfony/filesystem
Version ^6.4 | ^7.0 | ^8.0
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform