Package Health

yii3-extensions/asset-fontawesome-free

The package is small but well structured, with tests, release notes, a matching source tree, and clear licensing. Its workflow references are all unpinned, and no security policy is published.

Latest 0.1.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

Only two releases were published, with the latest on January 23, 2024 and none in the last 12 months. The repository was updated later, which partly offsets the registry inactivity but does not restore release confidence.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. The later repository push is compensating evidence, but current maintenance capacity remains uncertain.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations unclear. Dependabot provides some compensating security hygiene.

Version stabilitycaution

Version 0.1.1 is a stable, non-prerelease release, but it remains below a stable major version and has little release history.

Workflow auditcaution

All five workflows were analyzed without high-confidence audit findings or untrusted checkouts, but all five action references are unpinned. That weakens build reproducibility and supply-chain hygiene without making the package unfit on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/files
Version ^2.0
php-forge/foxy
Version ^0.1
yiisoft/assets
Version ^4.0

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform