Package Health

wizdam/wizdam-editorial

Recent commits from two contributors, a license, artifact tests, and a security policy provide useful maintenance evidence. Ten of eleven workflow actions are unpinned, weakening build reproducibility; verify the source before adopting.

Latest v1.0.0.0PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update scripts, which increases installation complexity and warrants more trust in the package's source and release process.

Release historycaution

This is the only release, published 148 days after the first release date, so the package has little registry history to demonstrate maturity or sustained maintenance.

Repo package mentioncaution

The linked repository is named lumera-edge and neither matches the package name nor mentions it in its README, so its ownership of this release is unclear.

Workflow auditcaution

The audit covered all four workflows with no untrusted checkouts or injection findings, but 10 of 11 action references are unpinned, leaving build inputs vulnerable to silent changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rochmady

Direct Dependencies

DependencyLast ReleaseScore
mpdf/mpdf
Version ^8.0
—
—
setasign/fpdi
Version ^2.0
—
—
smarty/smarty
Version ^5.8
—
—
adodb/adodb-php
Version ^5.22
—
—
vlucas/phpdotenv
Version ^5.5
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform