Package Health

vivutio/skeleton

An empty vivutio installation: the core and nothing else, the same for every supplier, operator and agent. Add the modules that apply to you.

Latest v0.1.5PackagistPackagist

58%

Total Score

caution

A two-day-old package has one active contributor and a high-confidence release-workflow issue with every action unpinned.

Health Score Breakdown

Workflow auditdanger

The audit covered both workflows and found a high-confidence template-injection issue in release.yml; all six action references are unpinned, and one workflow grants top-level write access. No untrusted checkout or script-injection trigger was found to compound the issue.

Lifecycle scriptscaution

Composer runs post-install and post-update scripts, which is common for Symfony packages but adds install-time behavior that consumers should understand.

Release historycaution

Six releases in two days show active development, but a package age of only two days provides almost no evidence of long-term maintenance or release discipline.

Repo bus factorcaution

One contributor made all six recent commits, creating a low bus factor. Organization ownership provides some handoff capacity, but no second active contributor is shown.

Repo commit activitycaution

Six commits in the last three months, all concentrated in one active maintainer, show recent work but limited evidence of sustained maintenance capacity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ezekiel Mjema

Direct Dependencies

DependencyLast ReleaseScore
symfony/flex
Version ^2.11
—
—
symfony/yaml
Version 8.1.*
—
—
symfony/dotenv
Version 8.1.*
—
—
symfony/console
Version 8.1.*
—
—
symfony/runtime
Version 8.1.*
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
4 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform