Package Health

@graphql-tools/graphql-file-loader

A set of utils for faster development of GraphQL tools

Latest 8.1.22NPMNPM

88%

Total Score

healthy

Healthy: frequent releases and recent repository activity outweigh minor workflow and package-linkage hygiene concerns.

Health Score Breakdown

Maintainerscaution

Three publishing accounts use gmail.com addresses (urigo, ardatan, and enisdenjo), which is account-hygiene risk despite the primary the-guild.dev domain and five total publishers.

Project backingcaution

The repository is owned by a user account rather than an organization, so there is no explicit organizational handoff signal to offset contributor concentration.

Repo bus factorcaution

One contributor made 62.5% of recent commits, which is concentrated, but seven other contributors were active during the same three-month period.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention this package, creating some uncertainty about the package-to-repository linkage; the package name mismatch can also occur for monorepo subpackages.

Workflow auditcaution

All four workflows were analyzed with no audit findings or untrusted checkouts. Eight of 22 action references are unpinned and two workflows have top-level write permissions, creating minor hygiene concerns without an observed exploit path.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.4.0
—
—
globby
Version ^11.0.3
—
—
unixify
Version ^1.0.0
—
—
@graphql-tools/utils
Version ^12.0.3
—
—
@graphql-tools/import
Version ^7.2.2
—
—

Weekly Downloads

Info

Last Published
11 days ago
Created
6 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform