Package Health

amplify/utility

This release appears usable but warrants caution. It has a stable non-prerelease version, regular release activity over roughly 12 months, no registry deprecation, an unarchived repository, a substantial 64-file implementation, and organization-owned project backing. However, recent repository activity is minimal at two commits in three months and concentrated entirely in one contributor, while the package and repository lack README, tests, and changelog files; the repository also does not match the package name and does not provide a detectable README mention. Missing security scanning and a security policy further reduce transparency, although the workflow showed no analyzed dangerous patterns and the package has a declared GPL-3.0-or-later license. Depend on it only after reviewing its compatibility and maintenance expectations.

Latest 1.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. That is not inherently concerning because the linked repository is organization-owned, but it still leaves registry publishing dependent on a narrow account base.

Package scaffoldingcaution

The artifact and repository provide no README, tests, or changelog. GitHub Releases are enabled, but the supplied signal does not show that release notes compensate for the broader documentation and testing gaps.

Repo bus factorcaution

All two recent commits came from one contributor, creating a concentrated maintenance dependency. Organization ownership partially mitigates handoff risk, but no second active contributor is shown.

Repo commit activitycaution

Only two commits were made in the last three months by one active maintainer, which is a limited recent maintenance pace despite the stronger release history.

Repo issue activitycaution

There are no open issues or pull requests, no issue activity in the last month, and one merged pull request. This is compatible with a small project but offers little evidence of a broad maintenance or user-support community.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Hafijul Islam

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
26 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform