Package Health

windwalker/reactor

The package has a clear MIT license, stable releases, and an organization-backed repository with a very small runtime dependency surface. Missing security scanning and unpinned workflow actions leave maintenance and build hygiene weaker than its release cadence suggests.

Latest 4.2.9PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, despite a recent registry release; this creates a meaningful maintenance-capacity concern.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, indicating limited visible adoption; popularity is supporting evidence, so this is a modest concern rather than a decisive risk.

Repo toolingcaution

Composer is used for builds, but no security-scanning tool is configured, leaving automated security hygiene weaker than ideal.

Security policycaution

The repository has no published security policy, reducing transparency about how vulnerability reports are handled.

Workflow auditcaution

The sole workflow was fully analyzed with no detected injection or high-severity findings, but all three action references are unpinned; the missing top-level permissions block is acceptable on its own, while unpinned actions weaken supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
11 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform