Package Health

yaleksandr89/oauth2-yandex

The package has clear documentation, tests, a security policy, and active recent releases. Its workflow scopes permissions read-only, but all seven action references are unpinned, leaving avoidable build-reproducibility risk.

Latest v1.0.7PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Project backingcaution

The package and repository are owned by the same individual account, so the observed single-person maintenance pattern is not backed by an organization handoff structure.

Repo bus factorcaution

One contributor made all 16 commits in the last 3 months, concentrating maintenance knowledge and creating a meaningful continuity risk.

Workflow auditcaution

The sole workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout, script-injection, or high-confidence audit findings. However, all 7 of 7 action references are unpinned, so workflow inputs are not fully reproducible.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Александр Юрченко

Direct Dependencies

DependencyLast ReleaseScore
psr/http-message
Version ^1.1 || ^2.0
—
—
league/oauth2-client
Version ^2.9
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform