Package Health

webhook-ledger/webhook-ledger-bundle

The package includes a substantial README and tests, plus a repository license and security policy. Its single-person ownership and missing security scanning add some maintenance uncertainty.

Latest v1.0.2PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

One registry maintainer is a modest bus-factor concern for a user-owned project, with no organization backing shown to compensate for that narrow publishing base.

Release historycaution

The package was released three times within its first day, showing active initial publishing but not yet enough history to demonstrate sustained maintenance.

Repo commit activitycaution

No commits or active maintainers were observed in the last three months. Because the package is only about one day old, this primarily indicates limited maturity rather than established abandonment.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful repository hygiene gap for a package handling webhook data.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, reducing build reproducibility and supply-chain protection.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1 || ^2 || ^3
—
—
symfony/uid
Version ^7.0 || ^8.0
—
—
doctrine/orm
Version ^3.0
—
—
doctrine/dbal
Version ^3.8.2 || ^4.0
—
—
symfony/config
Version ^7.0 || ^8.0
—
—

Weekly Downloads

Info

Last Published
8 days ago
Created
9 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform