Package Health

yard/brave-csp

This release appears healthy and suitable to depend on: it has a clear license, stable non-prerelease versioning, 31 releases over 637 days with 17 in the last 12 months, recent repository activity, five active contributors, and organization backing. The package is small and purpose-specific, so its limited file tree and lack of packaged tests or changelog are modest transparency gaps rather than strong abandonment indicators. The main cautions are the absence of a security policy and explicit top-level workflow token permissions, although the analyzed workflows show no dangerous trigger, checkout, or script-injection patterns.

Latest v1.5.3PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

A 1,458-character README documents installation, features, and usage, but neither the artifact nor repository contains tests or a changelog. For this small policy package, the missing tests and changelog are a modest transparency gap, partially offset by active releases and GitHub Releases usage.

Repo popularitycaution

The repository has only 1 star and 0 forks, indicating limited public adoption. Popularity is supporting evidence rather than a verdict, and the low counts are outweighed by recent release and contributor activity.

Security policycaution

The repository has no SECURITY.md or other security policy. This is a genuine disclosure and maintenance gap, though it is not evidence that the package is abandoned.

Token permissionscaution

All 4 workflows lack top-level token permissions declarations, leaving permissions less explicit than recommended. However, none declares top-level write access, so this is a hygiene caution rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
spatie/laravel-csp
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
28 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform