Package Health

collei/collection

This is a usable but immature package with a clear MIT license, matching repository, stable non-prerelease version, recent publication activity, and no deprecation or install-time scripts. However, it is only 95 days old, has just three releases, only two commits in the last three months, and all recent commits come from one contributor. The very short README, absence of tests and changelog, lack of security scanning and security policy, and zero repository popularity add transparency and maintenance concerns. It is reasonable for lower-risk use, but adoption should account for its limited track record and single-maintainer dependency.

Latest v1.0.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. That is a limited publishing base, and no organization backing is present in the provided project context to compensate for it.

Package scaffoldingcaution

A README is present, but it is only 21 characters and the package and repository contain neither tests nor a changelog. GitHub Releases provide some release documentation, but the overall project documentation and validation surface remain thin.

Project backingcaution

The repository is owned by an individual user rather than an organization. Combined with the single active contributor, this provides no visible organizational redundancy.

Release historycaution

The package is young at 95 days old with three releases and a median release interval of about 48 days. This shows ongoing publication but provides only a limited maintenance track record.

Repo bus factorcaution

One contributor made all two commits in the last three months, giving a 100% top-contributor share. This creates a clear continuity risk because no second active contributor is shown.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Al Ju

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
19 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform