Package Health

tourze/wechat-work-security-bundle

Tests, a license, and a matching repository provide useful transparency. The package has little usage evidence and its automated actions are not pinned, so pinning this exact release is safer than tracking updates.

Latest 0.0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historydanger

This is the only release, published about 1 year and 4 months ago, with no releases in the last 12 months. That limited history makes ongoing maintenance uncertain.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last 3 months, despite being unarchived. This is a meaningful maintenance concern for a young package.

Security policycaution

The repository has no security policy. This is a transparency and reporting gap, though it is partly offset by the presence of tests and workflow checks.

Workflow auditcaution

Both workflows were analyzed successfully and no dangerous audit findings were reported, but all 4 action references are unpinned. That leaves avoidable build-integrity exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
doctrine/orm
Version ^3.0
—
—
symfony/yaml
Version ^6.4 || ^7.1
—
—
doctrine/dbal
Version ^4.0
—
—
nesbot/carbon
Version ^2.72 || ^3
—
—
symfony/config
Version ^6.4
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform