Package Health

cu-boulder/boulder_d9_base

University of Colorado Boulder base theme

Latest 20260909PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Package scaffoldingcaution

A substantive README and changelog are present, and the README documents installation and linting. Tests are absent from both the artifact and repository, which is a modest hygiene gap for a theme package but not by itself a severe dependency risk.

Repo package mentioncaution

The linked repository name does not match the package name and its README does not mention the package, creating a meaningful risk that the repository relationship is unclear or that the package is using a broader project repository. The README excerpt references boulder_base and the repository is a CU Boulder theme repository, which partially explains the naming difference but does not remove the provenance uncertainty.

Repo popularitycaution

The repository has only 3 stars and no forks, so external adoption evidence is limited. Popularity is supporting evidence rather than a decisive health requirement, especially given the active release and commit signals.

Repo toolingcaution

Composer is used as a build tool, but no security scanning tools were detected. The missing scanning coverage is a transparency and assurance gap, though it is partly offset by the active repository and safe workflow analysis.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
27 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform