Package Health

paulo-hortelan/onmt

The package has a clear README, repository tests, a changelog, frequent releases, and active recent commits. Its concentrated ownership and workflow hygiene require extra care for long-term operations.

Latest v1.11.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump install-time script. This is a supply-chain consideration because dependency installation executes package code, though the signal does not establish that the script is unsafe.

Project backingcaution

The repository owner is an individual user rather than an organization, so there is no organizational handoff capacity to compensate for concentrated maintenance.

Repo bus factorcaution

One contributor made all 11 commits in the last 3 months, giving the project a very low bus factor. The active release cadence helps, but does not remove the risk if that maintainer becomes unavailable.

Security policycaution

The repository has no security policy. For a package that manages network equipment connections, this reduces the clarity of vulnerability-reporting and response expectations.

Workflow auditcaution

All three workflows were analyzed, but all six action references are unpinned. A high-confidence bot-conditions finding affects a pull_request_target workflow, while two workflows grant top-level write permissions; together these are meaningful workflow-hygiene concerns without proving the release is unsafe.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

paulo-hortelan

Direct Dependencies

DependencyLast ReleaseScore
illuminate/contracts
Version ^10.0|^11.0|^12.0|^13.0
—
—
spatie/laravel-package-tools
Version ^1.14.0
—
—

Weekly Downloads

Info

Last Published
8 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform