Package Health

lyrasoft/eva

Regular releases and an organization-owned repository provide useful continuity. No commits in the last three months, absent security policy, and high-confidence workflow injection findings leave meaningful maintenance and automation concerns.

Latest 1.3.10PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, a material sign of slowed development that is only partly offset by recent registry releases.

Repo issue activitycaution

There were 23 open issues but no new or closed issues and no merged pull requests in the last month, reinforcing the lack of recent repository activity.

Security policycaution

The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a project with substantial runtime functionality.

Workflow auditcaution

All 12 action references are unpinned, and the audit found two high-confidence template-injection findings in img-sizes.yml that may expand attacker-controlled input into code; no dangerous trigger or untrusted checkout was reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Simon Asika

Direct Dependencies

DependencyLast ReleaseScore
lyrasoft/luna
Version ^2.2
windwalker/di
Version ^4.0
symfony/mailer
Version ^6.0||^7.0||^8.0
windwalker/dom
Version ^4.0
windwalker/orm
Version ^4.0

Weekly Downloads

Info

Last Published
5 months ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform