Package Health

decodelabs/systemic

The package has clear consumer documentation, a permissive license, and a long release history backed by an organization. Build-workflow pinning and the lack of a security policy reduce confidence, while the absence of commits in the last three months warrants monitoring.

Latest v0.12.4PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Continued registry releases partly offset this, but the recent source inactivity is a real maintenance concern.

Repo toolingcaution

The repository uses Composer, but no security-scanning tools were detected. For a package that launches processes and accesses system information, this is a modest transparency and maintenance gap.

Security policycaution

No security policy was found in the repository. This does not show a security defect, but it leaves vulnerability-reporting expectations and project response practices unclear.

Workflow auditcaution

The single workflow was fully analyzed with no high-confidence audit findings or dangerous untrusted triggers, but all 7 action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Tom Wright

Direct Dependencies

DependencyLast ReleaseScore
decodelabs/nuance
Version ^0.2
decodelabs/kingdom
Version ^0.2
decodelabs/coercion
Version ^0.3.5
decodelabs/eventful
Version ^0.4.5
decodelabs/fluidity
Version ^0.3.7

Weekly Downloads

Info

Last Published
11 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform