Package Health

oskarstark/no-floc-listener

The package is small, licensed, tested, and clearly tied to its source repository, with no install-time scripts or deprecation notice. Registry releases have stopped for nearly three years, while the workflow uses 10 unpinned actions and the repository has no security policy.

Latest 1.1.0PackagistPackagist

70%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The latest registry release was in December 2023, nearly three years ago, with no releases in the last 12 months. This lowers confidence in ongoing maintenance, although the seven-release history shows the package was previously established.

Security policycaution

The repository has no security policy. For a small library this is a modest transparency gap rather than evidence of unsafe code, but it gives users no documented vulnerability-reporting path.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 10 action references are unpinned, leaving avoidable update and supply-chain exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Oskar Stark

Direct Dependencies

DependencyLast ReleaseScore
symfony/http-kernel
Version ^5.3 || ^6.0 || ^7.0
—
—
symfony/event-dispatcher
Version ^5.0 || ^6.0 || ^7.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform