Package Health

riverline/multipart-parser

A clear README, repository tests, release notes, and an MIT license support adoption. The workflow is fully audited with read-only permissions, but its two action references are unpinned and the project has no published security policy.

Latest 2.2.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Repo commit activitycaution

The repository recorded no commits and no active maintainers during the last three months. This is a maintenance concern, although the recent release provides some compensating evidence.

Repo toolingcaution

Composer is used for the build, but no security scanning tooling is reported. The absence of scanning is a hygiene gap rather than evidence of abandonment.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a library that parses multipart content.

Workflow auditcaution

The only workflow was fully analyzed, uses read-only permissions, and has no dangerous sinks or audit findings. However, both action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2024-10404 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
riverline/multipart-parser is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.1.1.
2.0.0 - 2.1.1
Low

Package versions

Maintainers

Romain Cambien
Riverline

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform