Package Health

coquibot/coqui

This release appears actively maintained and generally suitable to evaluate as a dependency: it has 12 releases over 188 days, the latest release is recent, the repository is not archived, and it has substantial recent commit activity from two contributors. The package is well documented and the repository contains tests, CI, release, and Docker workflows, while the MIT license and lack of install-time scripts reduce adoption risk. The main concerns are its very early 0.0.x maturity, low repository popularity, reliance on a small contributor base with one contributor responsible for about 72% of recent commits, and incomplete security hygiene, including no security policy and permissive or unspecified workflow token permissions. These warrant review and monitoring rather than ruling out the package.

Latest v0.0.31PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Carmelo Santana

Direct Dependencies

DependencyLast ReleaseScore
react/http
Version ^1.11
react/async
Version ^4
symfony/console
Version ^8.0
yethee/tiktoken
Version ^1.0
opis/json-schema
Version ^2.3

Weekly Downloads

Info

Last Published
15 days ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform