Package Health

automattic/sliding-window-counter

The source repository is backed by Automattic, includes tests and security scanning, and published release notes document this version. Maintenance has slowed, with no commits in the last 3 months, while a high-confidence workflow audit found an unpinned container image.

Latest 0.6PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months, indicating a recent maintenance lull; the recent 0.6 release and organizational backing partly offset abandonment concerns.

Repo popularitycaution

The repository has only 3 stars and 3 forks, showing limited community adoption; this is supporting evidence rather than a decisive health problem.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations unclear despite its use of security scanning tools.

Version stabilitycaution

Version 0.6 is a non-prerelease release, though it remains before a stable major version and may carry more API-change risk than a 1.x release.

Workflow auditcaution

All four workflows were analyzed with no untrusted checkouts or script injection, but a high-confidence finding reports an unpinned container image and 9 of 13 action references are unpinned, weakening build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexey Kopytko

Direct Dependencies

DependencyLast ReleaseScore
sanmai/pipeline
Version ^6.11
—
—
tumblr/chorus-timekeeper
Version ^0.1.0
—
—

Weekly Downloads

Info

Last Published
10 months ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform