Package Health

yireo/magento2-page-cache-csp-nonce-regenerator

The package is clearly documented, licensed, and has a security policy. CI's floating images weaken build reproducibility; pin this version while confirming Magento compatibility.

Latest 0.0.2PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historycaution

Only two releases were published, with the latest about two years ago and none in the last 12 months. Recent repository commits provide some compensating maintenance evidence, but registry delivery is sparse.

Repo bus factorcaution

One contributor made all five recent commits, concentrating maintenance responsibility. Organization backing partly reduces handoff risk, but no second active contributor is shown.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency gap rather than evidence of unsafe code.

Version stabilitycaution

Version 0.0.2 is not a prerelease, but the package remains below major version 1, so compatibility expectations are less mature.

Workflow auditcaution

All five workflows were analyzed without untrusted triggers or script injection, but four high-confidence findings identify unpinned container images, including floating latest tags. This weakens reproducibility and build integrity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
magento/framework
Version ^103.0
—
—
magento/module-csp
Version ^100.0
—
—
magento/module-page-cache
Version ^100.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform