Package Health

axenox/gantt-js

Its workflows use broad write access and unpinned actions, with high-confidence template-injection findings. No security policy is published, although the package is licensed and includes tests and release notes.

Latest v1.1.1PackagistPackagist

61%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

This release is the package's first and was published 0 days ago, so there is no track record for stability or sustained maintenance yet.

Repo bus factorcaution

All 52 recent commits came from one contributor, leaving maintenance dependent on a single person; the repository owner is a user account rather than an organization.

Security policycaution

The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.

Workflow auditcaution

Both workflows grant top-level write permissions, all 5 action references are unpinned, and high-confidence template-injection findings were reported in both workflows. No dangerous trigger or untrusted checkout was observed, so this is a workflow-hygiene caution rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sergej Riel

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 days ago
Created
6 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform