Package Health

sanderdlm/skeleton

Skeleton for a PHP project

Latest 2.6PackagistPackagist

68%

Total Score

caution

Usable with caveats: recent release activity is offset by three quiet months and unpinned workflow actions.

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. Although the registry shows frequent releases and the repository was pushed recently, the recent development pause is a meaningful maintenance concern.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. This modestly reduces ongoing supply-chain assurance.

Security policycaution

The linked repository has no security policy. That leaves vulnerability reporting and response expectations undocumented.

Workflow auditcaution

The single workflow was fully analyzed and uses read-only permissions, with no untrusted checkout or injection findings. However, all 5 action references are unpinned, leaving them exposed to upstream reference changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.22
—
—
php-di/php-di
Version ^7.1
—
—
nikic/fast-route
Version ^1.3
—
—
vlucas/phpdotenv
Version ^5.6
—
—
middlewares/fast-route
Version ^2.1
—
—

Weekly Downloads

Info

Last Published
8 months ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform