Package Health

chieftools/dns-resolver

This is a usable but relatively young package with clear licensing, a matching organization-backed repository, active release publishing, repository tests, security documentation, Dependabot, and no deprecation or dangerous workflow findings. However, it has only 153 days of history, releases are unusually clustered, repository commit activity shows no commits or active maintainers in the last 3 months, repository popularity is minimal, and the CI workflow does not declare top-level token permissions. The repository evidence partly offsets the artifact's missing tests and changelog, but the limited demonstrated maintenance history warrants caution before adopting it as a critical dependency.

Latest v1.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

Fourteen releases over 153 days show active publishing, but the median release interval is about 50 minutes, indicating an unusually clustered and still-maturing release history rather than long-established stability.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the repository was recently pushed and releases are active, the absence of sustained commit activity is a meaningful maintenance concern for a young package.

Repo issue activitycaution

There are no open issues and one open pull request, but no issues or pull requests were closed or merged in the last month. This offers limited evidence of active community maintenance.

Repo popularitycaution

The repository has only 1 star, 1 fork, and 0 watchers. This provides little external adoption evidence, although low popularity alone is not a decisive health concern for a specialized package.

Token permissionscaution

The only workflow lacks top-level token permissions. No write permissions were observed, but the absence of an explicit least-privilege declaration is a CI hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
mikepultz/netdns2
Version ^2.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform