Package Health

symplify/vendor-patches

Generate vendor patches for packages with single command

Latest 12.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitycaution

Only one commit was recorded in the last 3 months, which is a weak recent maintenance signal despite the separate release and pull-request activity.

Repo toolingcaution

The project uses Composer for builds but reports no security scanning tooling, leaving a modest transparency and supply-chain hygiene gap.

Security policycaution

The repository has no security policy, so vulnerability reporting and response expectations are not documented.

Workflow auditcaution

All three workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all seven action references are unpinned, weakening build reproducibility and action-integrity protection.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
entropy/entropy
Version ^0.4
—
—
webmozart/assert
Version ^2.1
—
—
cweagans/composer-patches
Version ^1.7.3 || ^2.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform