Package Health

xiidea/easy-audit

The package has a clear MIT license, useful documentation, repository tests, and a long release history with a recent release. No commits in the last three months and three unpinned workflow actions weaken maintenance confidence and build reproducibility.

Latest 3.0.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitycaution

There were zero commits and zero active maintainers in the last three months, which is a meaningful sign of currently quiet maintenance; the recent release and non-archived repository partly offset it.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, while nine issues and three pull requests remain open; this adds a modest sign of limited recent project attention.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a transparency and maintenance-hygiene gap.

Security policycaution

The repository has no published security policy, reducing guidance for reporting and handling vulnerabilities, though this does not by itself indicate abandonment.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned, weakening build reproducibility. The missing top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Roni Saha
EasyAuditBundle Community

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1|^2|^3
—
—
symfony/security-bundle
Version >=5.4 <8.0
—
—
symfony/framework-bundle
Version >=5.4 <8.0
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform