Package Health

webproject-xyz/codeception-module-ai-reporter

Clear documentation, tests, and release notes make the package easy to evaluate. The organization-backed project is active and dependencies are modest, but its workflow shares credentials broadly and lacks a security policy.

Latest 2.1.0PackagistPackagist

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though active development and security scanning partly compensate.

Workflow auditcaution

The single workflow has no untrusted checkout or script-injection findings and pins its analyzed action, but it uses top-level write permissions and a high-confidence medium-severity secrets-inherit finding. Those credentials broaden workflow exposure and warrant review.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benjamin Fahl

Direct Dependencies

DependencyLast ReleaseScore
webmozart/assert
Version ^1.12.1 || ^2.4.1
—
—
codeception/codeception
Version ^5.3.5
—
—

Weekly Downloads

Info

Last Published
6 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform