Package Health

voku/slop-scan

The project includes tests, release notes, and security scanning, with no install-time scripts. Its pre-1.0 status and missing security policy warrant normal dependency review.

Latest 0.1.14PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

Two contributors were active, but one made 38 of 44 commits, or about 86%. The second contributor provides some continuity, but maintenance remains concentrated.

Security policycaution

The repository has no security policy. This is a transparency and response-process gap, although the reported security-scanning tools provide partial compensation.

Version stabilitycaution

Version 0.1.14 is not yet at a stable major version, so compatibility may change more readily than in a mature 1.x package. It is not marked as a prerelease, which partly offsets that concern.

Workflow auditcaution

All three workflows were analyzed with no untrusted checkouts, script injections, or audit findings. However, all seven action references are unpinned and two workflows grant top-level write permissions, creating moderate workflow hygiene concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Lars Moelleken

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^7.4
—
—
helgesverre/toon
Version ^3.2
—
—
nikic/php-parser
Version ^5.8
—
—
voku/simple-php-code-parser
Version ^0.22.5
—
—

Weekly Downloads

Info

Last Published
1 day ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform