Package Health

nswdpc/ci-files

Collection of files for use in CI

Latest 4.2.0PackagistPackagist

68%

Total Score

caution

Usable with caveats—one-person maintenance and all workflow actions unpinned weaken confidence.

Health Score Breakdown

Dependency profilecaution

The package declares five runtime dependencies, including CI and analysis tools; that is substantial for a collection of CI files but consistent with its stated purpose.

Repo bus factorcaution

The repository is organization-owned, which provides some handoff capacity, but one contributor made 100% of recent commits and no second contributor was active.

Repo toolingcaution

Composer is used for builds, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no security policy, so vulnerability reporting and response expectations are not documented.

Workflow auditcaution

All 28 workflows were analyzed without failures and have no untrusted checkouts or script-injection findings. However, all 12 analyzed action references are unpinned, and high-confidence template-injection findings are present; template injection alone is workflow hygiene, while the complete audit limits uncertainty.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
rector/rector
Version ^2
—
—
phpstan/phpstan
Version <2.2.6||^2.2.7
—
—
phpunit/phpunit
Version ^9.5 || ^10 || ^11
—
—
friendsofphp/php-cs-fixer
Version ^3
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform