Package Health

rainlab/user-plugin

This is a healthy, actively maintained release with a long release history, frequent recent releases, stable versioning, an unarchived matching repository, and current commit and issue activity from two active contributors. The organization-backed project and repository/package alignment reduce concerns from the small registry maintainer list and concentrated commit share. The main reservations are the absence of a security policy, undeclared top-level GitHub Actions permissions, and no configured security-scanning tool, but these are hygiene gaps rather than evidence of abandonment or an unfit dependency.

Latest v3.7.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool is configured. This is a modest supply-chain hygiene gap, not evidence that the package is unmaintained.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a genuine transparency and maintenance-process gap.

Token permissionscaution

The only workflow lacks top-level permissions, although no workflow requests top-level write access and no dangerous workflow patterns were found. The configuration is less explicit than preferred but presents limited observed risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2018-10366
rainlab/user-plugin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.4.5.
0.0.0 - 1.4.5
Medium

Package versions

Maintainers

Alexey Bobkov
Samuel Georges

Direct Dependencies

DependencyLast ReleaseScore
october/rain
Version >=3.0
firebase/php-jwt
Version ^6.4 || ^7.0
pragmarx/google2fa
Version ^8.0 || ^9.0
bacon/bacon-qr-code
Version ^2.0 || ^3.0
composer/installers
Version ~1.0

Weekly Downloads

Info

Last Published
9 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform