Package Health

alexminza/wc-alcohol

The package has a clear license, a recent release, and a small dependency footprint. Its repository uses Composer and security scanning, but it lacks a security policy and has limited maintenance depth.

Latest v1.2.1PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Project backingcaution

The registry package and repository are owned by the same individual user, confirming the repository is directly associated with the package. It also means the project has no indicated organizational backing to offset its concentrated maintenance.

Repo bus factorcaution

All recent commits came from one contributor, giving the project a single-person maintenance dependency. The repository is user-owned rather than organization-backed, so there is no provided compensating handoff signal.

Repo commit activitycaution

Only one commit was recorded in the last three months, from one active maintainer. Recent activity exists, but the low volume provides limited evidence of sustained maintenance capacity.

Security policycaution

No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not by itself evidence of unsafe code.

Workflow auditcaution

The single workflow was fully analyzed with no detected injection or high-confidence audit findings, but both of its two action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexander Minza

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform