Package Health

aisdk/meta

The package is only 66 days old, with three releases on the same day and five recent commits from one contributor. Readme, tests, MIT licensing, organization backing, security scanning, and read-only workflow permissions provide useful counterweight, though both workflow actions are unpinned.

Latest v0.8.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

At 66 days old, the package has only three releases, all published on the same day, so its maintenance history is still too short to demonstrate durable stability.

Repo bus factorcaution

All five recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, so this is a caution rather than a severe risk.

Repo commit activitycaution

Five commits were made in the last three months, showing recent activity, but the activity is too limited to establish a mature maintenance cadence.

Version stabilitycaution

Version v0.8.2 is not marked prerelease, which is positive, but it remains below a stable 1.0 major and the package has limited release history.

Workflow auditcaution

The only workflow was fully analyzed, uses read-only permissions, and has no dangerous audit findings. Both of its two action references are unpinned, which leaves a modest build-integrity weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
aisdk/core
Version ^0.8.0
aisdk/openai-compatible
Version ^0.8.0

Weekly Downloads

Info

Last Published
2 months ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform