Package Health

darsyn/ip

The project has recent commits, a fresh release, tests in its repository, documentation, and a security policy. The release is a prerelease, all 11 workflow actions are unpinned, and recent commits come from one contributor, so maintenance and build reproducibility deserve attention.

Latest 6.1.0-rc1PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Repo bus factorcaution

All 17 commits in the last three months came from one contributor, concentrating recent maintenance responsibility. Organization backing provides some handoff capacity, but no second active contributor is shown.

Repo toolingcaution

The repository uses Composer, but no security-scanning tool was detected. The security policy and other repository controls provide some transparency, so this is a modest hygiene gap rather than a major health concern.

Version stabilitycaution

Version 6.1.0-rc1 is a prerelease, so its API and behavior may still change before the stable release. The package is on an established major version and only 25% of recent releases were prereleases, limiting the concern.

Workflow auditcaution

Both workflows were analyzed successfully and no dangerous triggers, untrusted checkouts, script injections, or audit findings were reported. However, all 11 action references are unpinned, weakening build reproducibility; the absence of top-level permissions is not a concern by itself.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Zan Baldwin

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
7 days ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform