Package Health

nowo-tech/beacon-bundle

This release appears generally healthy and reasonable to adopt: it is actively developed, not deprecated or archived, has a stable major version, clear MIT licensing, documentation, tests, changelog, security policy, dependency automation, and a repository that references the package. The main concerns are the very young project age, unusually frequent releases, zero observed popularity, and strong concentration of recent commits in one human contributor, although organization ownership and a second active contributor partially mitigate the bus-factor risk. CI workflow permissions and untrusted workflow usage also deserve review before relying on the repository as a high-assurance supply-chain dependency.

Latest v1.8.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

Seven workflows were analyzed; one uses pull_request_target and one performs an untrusted checkout in a workflow_run context. No script-injection patterns were detected, but these workflow patterns warrant review because they can increase CI supply-chain exposure.

Release historycaution

The package is only 45 days old but has 40 releases, with a median interval of about 1 hour. This demonstrates active publishing, but the short history and unusually rapid cadence leave long-term stability less established.

Repo bus factorcaution

One contributor made 55 of 59 recent commits, or about 93%, which creates a meaningful concentration risk. The organization-owned repository and a second active contributor partially compensate, so this is caution rather than danger.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Given the package is only 45 days old, this is limited supporting evidence rather than a decisive abandonment concern, but external adoption is not yet demonstrated.

Token permissionscaution

Five workflows lack top-level permissions and two declare top-level write access, with no workflows showing read-only permissions. This is weaker least-privilege hygiene and merits review, although it does not establish that the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Héctor Franco Aceituno
Nowo.tech

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
psr/clock
Version ^1.0
symfony/config
Version ^7.0 || ^8.0
symfony/http-client
Version ^7.0 || ^8.0
symfony/http-kernel
Version ^7.0 || ^8.0

Weekly Downloads

Info

Last Published
20 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform