Package Health

ahmedde/unit-conversion

The repository has basic tests, release notes, and security scanning. One contributor and a single release limit confidence in long-term support, while workflow permissions and bot checks need attention.

Latest 1.0.0PackagistPackagist

60%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

Only one release exists, published 202 days ago, so there is little release history to establish sustained maintenance.

Repo bus factorcaution

All recent commits come from one contributor, leaving no demonstrated backup maintainer and increasing continuity risk for a user-owned project.

Repo commit activitycaution

The repository recorded one commit in the last three months from one active maintainer; recent activity exists, but the pace is too thin to demonstrate sustained maintenance.

Security policycaution

No repository security policy was found, so consumers have no documented channel for reporting vulnerabilities or receiving coordinated fixes.

Workflow auditcaution

All four workflows were analyzed, but every action reference is unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these are workflow hygiene concerns rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Ahmed Deghady

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform