Package Health

bishalshrestha/fynix

Healthy and reasonable to adopt, with a small maintenance risk. It is actively releasing, has repository tests and changelog coverage, and uses basic security tooling, but all recent commits come from one contributor and the project has very little community traction.

Latest v3.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Project backingcaution

The repository is owned by an individual user rather than an organization, which makes the single-contributor maintenance concentration more consequential.

Repo bus factorcaution

One contributor made all 12 recent commits, creating a genuine single-maintainer continuity risk. The project is user-owned rather than organization-backed, so there is no visible organizational handoff capacity to offset it.

Repo commit activitycaution

Twelve commits in the last 3 months show ongoing work, but all were made by one active maintainer, limiting resilience if that person becomes unavailable.

Repo popularitycaution

The repository has one star and no forks, so there is little evidence of external adoption or community support. This is supporting caution rather than a severe health concern because release and repository activity are strong.

Token permissionscaution

The CI workflow does not declare top-level token permissions. No write permissions were observed, but explicitly restricting the token would provide stronger workflow hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Bishal Shrestha

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
6 days ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform