Package Health

ralphjsmit/pest-plugin-filesystem

The source repository has tests, a changelog, and release notes, while the package is licensed and uses no install-time scripts. If you adopt it, pin the exact version and review its unpinned CI actions.

Latest 1.2.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

92

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The latest release was in February 2023, with no releases in the past 12 months despite the package being over four years old. This is a meaningful maintenance concern, although the repository remains unarchived and has a release note for this version.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the past three months, consistent with a long period of limited visible maintenance. The repository was last pushed in March 2024, which provides some evidence it was maintained previously but does not offset the current inactivity.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though the repository does include tests and a changelog.

Workflow auditcaution

All 5 of 5 analyzed action references are unpinned, creating avoidable build reproducibility and action-update risk. However, both workflows were fully analyzed, had no dangerous triggers or untrusted checkouts, and produced no audit findings, so this is a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
pestphp/pest
Version ^1.17
—
—
illuminate/support
Version ^8.76|^9.0|^10.0
—
—
pestphp/pest-plugin
Version ^1.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform