ohdearapp/ohdear-cli v5.3.0 appears to be a healthy dependency: it has been published for over 8 years with 41 releases, 13 releases in the last 12 months, a stable non-prerelease version, recent repository activity, two active contributors, an organization-backed repository, tests, build tooling, and a clear MIT license. The main concerns are limited recent commit volume, the absence of a repository security policy and dedicated security scanning, and permissive or unspecified GitHub Actions token permissions in several workflows. These are worthwhile supply-chain hygiene improvements but do not outweigh the package's strong maintenance and transparency evidence.
88%
Total Score
100
100
94
80
The repository uses Composer and Box for builds, but has no detected security-scanning tools. The build setup is positive; the missing dedicated scanning is a modest hygiene gap.
No repository security policy was found. This reduces vulnerability-reporting transparency, although it is a process gap rather than evidence of abandonment.
Three workflows lack top-level token permissions and one workflow declares top-level write permissions; no workflow has read-only permissions. This leaves GitHub Actions privilege boundaries less explicit than desirable.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.