Package Health

azure-oss/storage-common

This is a usable and currently maintained release with a stable major version, eight releases over the last 186 days, a recent repository push, a non-archived source repository, clear MIT licensing, and no install-time lifecycle scripts. The main concerns are that all 12 commits in the last 3 months came from one contributor, the repository has no tests or security scanning, and it has very little adoption evidence; organization ownership provides some maintenance continuity but does not eliminate the single-contributor risk. Overall, it appears reasonable to adopt with normal dependency review and monitoring, but it is not as resilient or transparent as a mature, broadly maintained package.

Latest 2.2.1PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Dependency profilecaution

The package has four runtime dependencies, a moderate and understandable dependency surface for an HTTP and Azure authentication library; no development dependencies are present, consistent with the absence of repository tests but offering less evidence of a maintained test setup.

Maintainerscaution

Only one registry account has publishing access. This is a concentration risk, although the linked repository is owned by an organization, which provides some compensating project backing.

Package scaffoldingcaution

A substantial README and changelog are present, and GitHub Releases are used, but neither the artifact nor the repository contains tests. For a low-level authentication and middleware library, the absence of repository tests is a meaningful maintenance and regression risk.

Repo bus factorcaution

One contributor made 100% of the 12 commits in the last 3 months, creating a real continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, so the signal shows no active issue resolution. Because issue counts are partly unknown and recent commits exist, this is a limited caution rather than a severe concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Brecht Vermeersch

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.8 || ^8.0
—
—
azure-oss/identity
Version ^1.0
—
—
caseyamcl/guzzle_retry_middleware
Version ^2.13 || ^3.0
—
—

Weekly Downloads

Info

Last Published
26 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform