Package Health

moonspot/phlag

The package includes tests, a clear BSD-3-Clause license, and useful documentation. Unpinned workflow actions and no security policy reduce build and disclosure transparency.

Latest 1.3.5PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Security policycaution

The repository has no security policy, which leaves vulnerability reporting and disclosure expectations unspecified. Active maintenance and Dependabot partly offset this transparency gap but do not remove it.

Workflow auditcaution

The only workflow was fully analyzed with no detected injection or high-confidence audit findings, but all three action references are unpinned. This weakens reproducibility and supply-chain hygiene without indicating an immediate severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Brian Moon

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.28
—
—
dealnews/db
Version ^4.1.0
—
—
pagemill/router
Version ^2.0
—
—
dealnews/get-config
Version ^2.2
—
—
phpmailer/phpmailer
Version ^7.1
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
10 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform