Package Health

alexskrypnyk/shell-variables-extractor

This release has strong evidence of active development and reasonable publication hygiene: it was released recently, has 8 releases in the last 12 months, uses a stable version, has a license, a substantial README, repository tests, and no install-time lifecycle scripts. However, the package is explicitly marked abandoned on Packagist in favor of alexskrypnyk/shellvar, which is a major adoption risk despite the linked repository remaining active. Maintenance is also concentrated in one contributor, the repository has no security policy, and workflow permissions are broader than ideal; the repository does not clearly identify or mention the published package name. This makes the release usable but a liability for a new dependency unless the replacement package is evaluated instead.

Latest 1.7.1PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Registry deprecationdanger

Packagist marks the package as abandoned and names alexskrypnyk/shellvar as its replacement. This is a severe dependency-selection risk even though other signals show recent activity.

Dangerous workflowscaution

One of five workflows uses pull_request_target, which warrants review because it runs with elevated event semantics. No untrusted checkout or script-injection patterns were detected, partially reducing the concern.

Repo bus factorcaution

One contributor made 100% of the three commits in the last 3 months. With a user-owned project rather than organization backing, this creates meaningful abandonment and handoff risk.

Repo commit activitycaution

There were 3 commits in the last 3 months, all from one active maintainer. Recent activity exists, but the low volume and concentration limit maintenance resilience.

Repo package mentioncaution

The repository name does not match the published package name and its README does not mention the package. This weakens provenance clarity and raises concern that the registry package may not be clearly tied to the linked repository.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alex Skrypnyk

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^7.4.18
alexskrypnyk/csvtable
Version ^1.2

Weekly Downloads

Info

Last Published
19 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform