Package Health

mrpunyapal/nativephp-plugin-impressions

The repository includes tests, a changelog, security policy, and dependency scanning. Its tiny release history and zero commits in the last three months leave maintenance capacity unproven; pinning workflow actions would improve build hygiene.

Latest v0.1.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is less than a day old with only two releases, so there is not enough history to establish mature release practices. Its recent publication explains the limited history but does not remove the uncertainty.

Repo commit activitycaution

No commits or active maintainers were observed in the last three months. Because the package was only released today, this is not evidence of abandonment, but maintenance capacity remains unproven.

Version stabilitycaution

Version v0.1.1 is not a prerelease, but the pre-1.0 version indicates an early-stage API with potentially limited stability.

Workflow auditcaution

The audit completed all four workflows without dangerous sinks or audit findings, but all 15 action references are unpinned and one workflow grants top-level write permissions. The unpinned actions are a build-integrity hygiene concern; the write permission is mild because no untrusted trigger or sink was observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
nativephp/mobile
Version ^4.5
—
—
illuminate/support
Version ^12.0|^13.0
—
—
illuminate/contracts
Version ^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
5 hours ago
Created
6 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform