Package Health

augmentedlogic/luceefer-client

This is a small, very young package with encouraging recent activity: four releases in 57 days, a latest repository push on the assessment date, no deprecation, and a non-archived organization-owned repository. However, adoption carries meaningful maturity and transparency concerns: the package has only seven files, no tests or changelog in either artifact or repository, just one active contributor with all five recent commits, no security scanning or security policy, and the linked repository neither matches the package name nor mentions it in its README. The rapid release cadence is positive but the pre-1.0 version and limited project evidence warrant caution before relying on it for a critical dependency.

Latest v0.3.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. Because the repository is organization-owned, this is not by itself severe, but it still leaves limited visible publishing redundancy.

Package scaffoldingcaution

A README is present, but it is only 40 characters and neither the artifact nor repository contains tests or a changelog. For a small client this is a genuine transparency and maintenance gap.

Repo bus factorcaution

One contributor holds 100% of the five commits in the last three months. Organization ownership provides some handoff potential, but no second active contributor is evidenced.

Repo commit activitycaution

Five commits occurred in the last three months, all by one active maintainer. Recent work is positive, but the limited volume and concentration reduce maintenance resilience.

Repo package mentioncaution

The repository name does not match the package name, and its README does not mention the package. Although name differences can be normal for subpackages, the complete lack of a README reference raises concern that the repository may not clearly document this package's provenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wolfgang Hauptfleisch

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
19 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform