Package Health

w3spi5/bigdump

Clear licensing, tests, release notes, and a two-person contributor base improve confidence. Pinning is the main remaining workflow hygiene gap; no dangerous triggers or audit findings were reported.

Latest v2.29PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is user-owned rather than organization-owned, so the small maintainer and contributor base provides less formal handoff capacity, though recent activity remains visible.

Repo toolingcaution

Composer is used for builds, which is appropriate, but no security-scanning tooling is reported; this is a minor transparency gap rather than evidence of poor maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations unclear for a web-facing database import tool.

Workflow auditcaution

Both workflows scope permissions at the job level and have no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, creating a workflow reproducibility and action-integrity gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexey Ozerov
w3spi5

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 months ago
Created
9 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform