Package Health

@ocavue/utils

@ocavue/utils 1.8.0 appears to be a healthy, actively maintained dependency: it is licensed, typed, non-deprecated, backed by a matching repository, reproducibly published with npm provenance, and has substantial test and build structure. The package has no runtime dependencies or install-time scripts, reducing operational and supply-chain exposure. The main concerns are that all five commits in the last three months came from one contributor, the repository has no security policy or configured security-scanning tools, and several workflows lack top-level token permissions; these are meaningful hygiene and continuity risks, but they are partly offset by recent release and pull-request activity, a current repository, safe workflow analysis, and clear package/repository alignment.

Latest 1.8.0NPMNPM

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Health Score Breakdown

Maintainerscaution

Only one registry publishing maintainer is listed, consistent with the user-owned project backing but still indicating concentrated publishing responsibility.

Repo bus factorcaution

One contributor made all five commits in the last three months, producing a complete single-contributor concentration; as this is a user-owned repository, there is no organization backing to compensate for the low bus factor.

Repo commit activitycaution

Five commits and one active maintainer were recorded in the last three months. The recent work is current but concentrated, so it supports maintenance while leaving continuity risk.

Repo popularitycaution

The repository has only 1 star and no forks, showing limited external adoption. This is supporting context rather than a health verdict, since popularity alone does not determine maintainability.

Repo toolingcaution

The repository uses TypeScript and Vitest for build and test tooling, but no security-scanning tools are configured. The missing scanning is a hygiene gap, not evidence of active compromise.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
10 days ago
Created
1 year ago
Unpacked Size
0.2 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform