Package Health

adrianmejias/pinecone

It includes clear documentation, tests in the source repository, an MIT license, and a clean workflow audit. Those strengths do not offset the absence of ongoing maintenance and the package’s withdrawn status.

Latest v1.0.12PackagistPackagist

12%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Using this package? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the package.

Release historydanger

The package has had no release in more than three years, with zero releases in the last 12 months. Its 13 releases were concentrated shortly after its April 2023 launch.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the archived project state and high abandonment risk.

Repository archiveddanger

The linked repository is archived, and its last push was in April 2023. Archived source indicates the project is no longer maintained.

Workflow auditcaution

Both workflows were analyzed with no audit findings, no untrusted checkouts, no script injection, and read-only permissions in one workflow. All five action references are unpinned, which is a minor reproducibility concern but not enough to change the overall verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adrian Mejias

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^6.3|^7.0
—
—
illuminate/support
Version ^6.0|^7.0|^8.0|^9.0|^10.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform