Package Health

udir-moodle/antivirus_mimeblocker

The license text needs clarification, and the automation has weak pinning and broad write access. The repository is not archived and includes usable documentation, but its maintenance record is too limited to support strong confidence.

Latest 2023022001PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Licensecaution

The manifest declares GPL-3.0-or-later, while the artifact license file is detected as AGPL-3.0; the release is licensed, but the mismatch reduces transparency.

Release historycaution

Only one release is recorded, with no established release cadence; this may reflect a newly mirrored package, but it provides little evidence of release maturity.

Repo commit activitycaution

The repository has no commits and no active maintainers in the last 3 months, leaving current maintenance capacity un demonstrated.

Security policycaution

No repository security policy is present, which weakens vulnerability-reporting transparency for a plugin that handles uploaded files.

Workflow auditcaution

The sole workflow gives top-level write permissions and both action references are unpinned. A high-confidence template-injection finding is present, but there is no untrusted trigger or checkout count tying it to an exploitable path, so this remains a hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
moodle/moodle
Version 3.10.* || 3.11.* || 3.5.* || 3.6.* || 3.7.* || 3.8.* || 3.9.* || 4.0.* || 4.1.*
—
—
composer/installers
Version ~1.0 || ~2.0
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
5 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform