Package Health

sandermuller/package-boost-php

The package has clear documentation, repository tests, release notes, and a source repository that matches the package. One publisher and only two recent commits limit maintenance redundancy, despite two active contributors.

Latest 1.0.0PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs both post-install-cmd and post-update-cmd scripts, so installation and updates execute package-defined code. That is a meaningful supply-chain consideration even though no malware finding is present.

Repo commit activitycaution

Only two commits were recorded in the last three months, which is limited activity for a package with frequent releases. Two active maintainers and the recent repository push partly offset abandonment concerns.

Security policycaution

The linked repository has no security policy, reducing transparency about vulnerability reporting and response. Dependabot and other repository evidence provide some compensating security practice, so this is a minor concern rather than a severe risk.

Workflow auditcaution

All 17 analyzed action references are unpinned, allowing workflow dependencies to change without a repository change; however, all five workflows were audited, four use read-only permissions, and no dangerous sinks or audit findings were reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sander Muller

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^7.0||^8.0
symfony/process
Version ^7.0||^8.0
sandermuller/boost-core
Version ^1.0
stolt/lean-package-validator
Version ^5.7||^6.0

Weekly Downloads

Info

Last Published
3 months ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform