Package Health

coral-media/ext-ta

The release has tests, a substantial README, and published release notes, but the repository shows no commits in the last three months. Broad workflow permissions and completely unpinned actions add maintenance and build-hygiene concerns.

Latest v1.0.1PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names ta-lib/ext-ta-lib as its replacement. That substantially weakens confidence in taking a dependency on this package, even though the release itself is not individually withdrawn.

Release historycaution

Only two releases exist over roughly seven months, with the latest released about seven months ago. This is limited history for judging long-term maintenance, though the package is still relatively young.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers over the last three months. That is consistent with a project that may have stopped receiving maintenance.

Repo package mentioncaution

The linked repository name does not match coral-media/ext-ta and its README does not mention the package. Organization backing makes a monorepo or publishing-layout explanation possible, but the package-to-source relationship is still less transparent.

Workflow auditcaution

Both analyzed workflows grant top-level write permissions, and all 10 action references are unpinned. No untrusted triggers, injection sinks, or auditor findings were reported, so this is a hygiene concern rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rafael Ernesto Espinosa Santiesteban

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 months ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform