Package Health

azaharizaman/nexus-audit

Clear package ownership, an MIT license, and substantial documentation support basic transparency. Pin v0.1.0-alpha1 because the project is still early and its maintenance evidence is limited.

Latest v0.1.0-alpha1PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

25

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, leaving little evidence of ongoing maintenance after the initial release.

Package scaffoldingcaution

A substantial README is present, which helps consumers integrate the library. Missing tests and changelog files are not packaging gaps for this published artifact, but the repository also reports no tests.

Project backingcaution

The registry namespace and repository are owned by the same individual account. This establishes ownership but provides only a narrow visible backing structure for a compliance-focused library.

Release historycaution

This is the only release, published 138 days after the package first appeared, so there is not enough release history to demonstrate sustained maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving security-maintenance practices less transparent.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Azahari Zaman

Direct Dependencies

DependencyLast ReleaseScore
symfony/uid
Version ^7.0
—
—
azaharizaman/nexus-crypto
Version dev-main
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform