Package Health

achyutn/filament-storage-monitor

This release appears generally suitable to depend on: it is a stable, non-deprecated v1 release with six releases in 148 days, recent repository activity, three active contributors, repository-backed tests, and a verified package/repository name match. The main concerns are the very recent project history, strong commit concentration in one contributor, absent security policy, and a pull_request_target workflow with an untrusted checkout; these warrant review before adoption but do not by themselves indicate abandonment or maliciousness. The MIT declaration, lack of install-time scripts, moderate dependency footprint, and read-only workflow permissions are positive factors.

Latest v1.4.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dangerous workflowscaution

The sole workflow uses pull_request_target together with an untrusted checkout, creating a meaningful CI security risk even though no script injection was detected.

Maintainerscaution

Only one account has registry publish access. This is a limitation in publishing continuity, although the repository shows three active contributors and the owner is an identifiable user account.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no organizational handoff capacity to offset the concentrated contributor base.

Release historycaution

Six releases over 148 days, with a median release interval of about 1.3 days, show active early development. The short project age means long-term maintenance is not yet established.

Repo bus factorcaution

Although three contributors were active, the top contributor made 31 of 33 commits, or about 94%, leaving maintenance substantially concentrated in one person.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Achyut Neupane

Direct Dependencies

DependencyLast ReleaseScore
filament/filament
Version ^4.0|^5.0

Weekly Downloads

Info

Last Published
10 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform