Package Health

compwright/should-retry

Usable with caveats: the package is licensed, documented, tested, and backed by a matching repository, but it has had only one release and no commits for about 18 months. Very low project adoption and limited security-policy and workflow-permission hygiene add maintenance risk.

Latest v1.0.0PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is the only release, published about 18 months ago, with no releases in the last 12 months. That limited history makes long-term maintenance uncertain.

Repo commit activitycaution

There were no commits and no active maintainers in the last three months. For a package with only one release, this is a meaningful indication of uncertain ongoing maintenance.

Repo popularitycaution

The repository has 1 star, 0 forks, and 1 watcher. Popularity is not decisive, but these very low figures provide little supporting evidence of community review or shared maintenance.

Repo toolingcaution

The repository uses Make and Composer build tooling, but no security-scanning tools were detected. This is a transparency and assurance gap rather than evidence that the package is unsafe.

Repository archivedcaution

The linked repository is not archived, although its last push was about 18 months ago, consistent with the package's limited recent activity.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jonathon Hill

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^1.0 || ^2.0 || ^3.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-message
Version ^1.0 || ^2.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform