Package Health

complex-heart/criteria

The small dependency set and MIT licensing keep adoption straightforward. Organization ownership and a recent release provide continuity, but maintenance is concentrated in one contributor and workflow references are not pinned.

Latest v4.3.0PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo bus factorcaution

All 2 commits in the last 3 months came from one contributor, concentrating recent maintenance knowledge despite the repository being owned by an organization.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations less transparent.

Workflow auditcaution

All 20 analyzed action references are unpinned, and the audit found high-confidence template-injection patterns plus a medium-confidence archived action. The template findings are in a release workflow without an observed untrusted checkout or script-injection sink, so they remain hygiene concerns rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Unay Santisteban

Direct Dependencies

DependencyLast ReleaseScore
complex-heart/domain-model
Version ^5.0.0 || ^6.0.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform