Package Health

nowo-tech/password-strength-bundle

The package is clearly documented and actively developed by an organization, with tests, security tooling, and a matching README reference. Workflow configuration needs remediation before adoption because an untrusted checkout is combined with a high-confidence template-injection finding, and all 22 actions are unpinned.

Latest v2.3.2PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Workflow auditdanger

The audit found a high-confidence template-injection issue in a workflow that also performs an untrusted checkout, creating a meaningful supply-chain risk. All 22 action references are unpinned, while the audit otherwise analyzed all six workflows successfully.

Repo bus factorcaution

Two contributors were active in the last three months, but one contributed about 73% of commits. Organizational ownership provides some handoff capacity, though contributor concentration remains a modest resilience concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Héctor Franco Aceituno
Nowo.tech

Direct Dependencies

DependencyLast ReleaseScore
symfony/form
Version ^6.0 || ^7.0 || ^8.0
—
—
symfony/config
Version ^6.0 || ^7.0 || ^8.0
—
—
symfony/validator
Version ^6.0 || ^7.0 || ^8.0
—
—
twig/extra-bundle
Version ^3.12
—
—
twig/string-extra
Version ^3.12
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform