Package Health

ohdearapp/ohdear-cli

ohdearapp/ohdear-cli v5.3.0 appears to be a healthy dependency: it has been published for over 8 years with 41 releases, 13 releases in the last 12 months, a stable non-prerelease version, recent repository activity, two active contributors, an organization-backed repository, tests, build tooling, and a clear MIT license. The main concerns are limited recent commit volume, the absence of a repository security policy and dedicated security scanning, and permissive or unspecified GitHub Actions token permissions in several workflows. These are worthwhile supply-chain hygiene improvements but do not outweigh the package's strong maintenance and transparency evidence.

Latest v5.3.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo toolingcaution

The repository uses Composer and Box for builds, but has no detected security-scanning tools. The build setup is positive; the missing dedicated scanning is a modest hygiene gap.

Security policycaution

No repository security policy was found. This reduces vulnerability-reporting transparency, although it is a process gap rather than evidence of abandonment.

Token permissionscaution

Three workflows lack top-level token permissions and one workflow declares top-level write permissions; no workflow has read-only permissions. This leaves GitHub Actions privilege boundaries less explicit than desirable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Freek Van der Herten

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
29 days ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform