Package Health

linkrobins/auto-lock

It includes integration tests, release notes, a clear license, and a small dependency surface. The project is only 38 days old, so its long-term maintenance is not yet proven; workflow pinning and security-policy gaps add modest concern.

Latest v1.0.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is a new package, only 38 days old, with one release and no established release cadence. That limits evidence of long-term maintenance but is partly offset by recent repository activity.

Repo bus factorcaution

Two contributors were active, but one accounts for about 78% of commits. Organization ownership provides some handoff capacity, so this is a modest concentration concern rather than a severe risk.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. That is a transparency and hygiene gap, not evidence of unsafe behavior by itself.

Security policycaution

The repository has no security policy. For a new package this reduces disclosure transparency, though the other provided signals show a real source repository and active development.

Workflow auditcaution

Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of the two action references are unpinned, which leaves a modest reproducibility and supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Link Robins

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform