Package Health

webproject-xyz/docker-hostsfile-sync

This release appears healthy and reasonable to depend on: it is a stable 1.x release with 32 releases over 536 days, 20 releases in the last 12 months, and a recent release, while the repository remains active and unarchived. The package and repository include a README, tests, changelog, CI and release workflows, a license, and a complete-looking Composer project structure. The organization-owned repository and two active contributors reduce the significance of the single registry maintainer. The main reservations are low repository popularity, no dedicated security scanning or security policy, and workflow permission and untrusted-checkout configuration that merits review before relying on the project for sensitive supply-chain use.

Latest 1.9.2PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Dangerous workflowscaution

No pull_request_target or script-injection workflows were detected, but one workflow uses an untrusted checkout in release.yml, which warrants review of release-trigger and credential handling.

Repo issue activitycaution

There is one open issue and two open pull requests, but no issues or pull requests were created or merged in the last month; this is a modest gap in visible community activity, partly offset by recent commits and releases.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. Low popularity is not decisive for a small utility, but it provides little external validation or community resilience.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a genuine security-hygiene gap, though it does not by itself indicate abandonment.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting and disclosure expectations unspecified.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Benjamin Fahl

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^8.1.6
—
—
symfony/runtime
Version ^8.1.0
—
—
symfony/serializer
Version ^8.1.6
—
—
symfony/http-client
Version ^8.1.6
—
—
phpstan/phpdoc-parser
Version ^2.3.5
—
—

Weekly Downloads

Info

Last Published
19 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform