Package Health

lullabot/drainpipe

Healthy and suitable to depend on, with one meaningful maintenance concern: all recent commits came from a single contributor. The organization-backed repository is active, releases are frequent, and the project has strong testing and security tooling.

Latest v6.2.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made all 16 commits in the last three months, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.

Repo commit activitycaution

There were 16 commits in the last three months, so development has not stopped. However, all recent activity came from one active maintainer, leaving limited observable contributor depth.

Security policycaution

No repository security policy was found, which is a transparency gap for reporting vulnerabilities. The presence of Gitleaks and CodeQL partially supports security practice but does not replace a disclosure policy.

Token permissionscaution

Most workflows use read-only permissions, but two omit top-level permissions and three declare top-level write access. This is a modest CI hardening concern rather than a severe risk, especially alongside the clean workflow analysis.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3
—
—
drush/drush
Version ^11||^12||^13
—
—
symfony/yaml
Version ^6||^7
—
—
vlucas/phpdotenv
Version ^4||^5
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform