Package Health

knplabs/gaufrette

Healthy and suitable to depend on. It has a long release history, a current release with documented changes, active contributors, tests and documentation, and clear organization backing; the main caveats are missing security-policy tooling and incomplete workflow permission declarations.

Latest v1.0.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo toolingcaution

The project uses Make and Composer build tooling, but no security-scanning tools were detected. This is a transparency and maintenance gap, though it is not severe given the other evidence.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting expectations unclear for a filesystem abstraction library.

Token permissionscaution

Three of four workflows lack top-level token permissions and one workflow grants top-level write access, providing weaker-than-ideal CI permission hygiene despite no detected dangerous workflow patterns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

KnpLabs Team
The contributors

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
14 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform