Package Health

astrotomic/iso639

Clear documentation, tests, release notes, and a matching repository make the package easy to evaluate. The organization-backed project is current and licensed, but its very small contributor base and unpinned workflow actions warrant monitoring.

Latest 1.1.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

Only two releases exist across roughly five years, with a median interval of about five years; the recent release shows activity but the overall cadence remains sparse.

Repo bus factorcaution

All three-month commit activity came from one contributor, leaving maintenance dependent on a single active person; organization ownership provides some handoff capacity but no second active contributor is shown.

Repo commit activitycaution

There was one commit in the last three months, showing some recent activity but not a strong maintenance cadence by itself.

Workflow auditcaution

All four workflows were analyzed with no detected dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all seven action references are unpinned, which weakens build reproducibility and supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tom Witkowski

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform