Package Health

nycorp/shortext-php

The package has clear licensing, documentation, tests, regular releases, and an active repository. Maintenance is concentrated in one contributor, while workflow permissions, unpinned actions, and a high-confidence automation warning add avoidable supply-chain risk.

Latest 1.0.14PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

25

Health Score Breakdown

Workflow auditdanger

All 12 action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The audit found no untrusted checkout or script-injection sinks, which limits the severity but does not remove the hygiene risk.

Maintainerscaution

Only one account has registry publishing access. The repository is user-owned rather than organization-owned, so the short maintainer base is a genuine continuity concern.

Project backingcaution

The source repository is owned by a user account rather than an organization, so the single-contributor and single-publisher concentration is not offset by visible organizational backing.

Repo bus factorcaution

One contributor made all commits in the last three months, leaving maintenance fully concentrated in a single person with no provided organizational backing.

Repo commit activitycaution

Only one commit was recorded in the last three months, indicating limited recent development despite the package's recent release activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Yvan Ngalle

Direct Dependencies

DependencyLast ReleaseScore
nycorp/lite-api
Version ^1.1
—
—
illuminate/contracts
Version ^10.0||^11.0||^12.0
—
—
spatie/laravel-package-tools
Version ^1.16
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform