Package Health

diablomedia/zym-message

The package is feature complete, tested, licensed, and recently released, but maintenance is intentionally infrequent. The workflow audit also found a high-confidence bot-condition issue and all five actions are unpinned.

Latest 1.0.4PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

Only five releases have been published since December 2021, with a median interval of about 449 days and one release in the last 12 months. This fits a feature-complete package but indicates sparse maintenance.

Repo commit activitycaution

The repository had zero commits and zero active maintainers in the last three months. Recent release activity partly offsets this, but the absence of coding activity raises maintenance risk.

Repo popularitycaution

The repository has no stars or forks and only two watchers, indicating a small user base. Popularity is supporting evidence rather than a health verdict, so this has limited weight.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting guidance undocumented. This is a modest transparency gap for a maintained library.

Workflow auditcaution

The audit found a high-confidence bot-condition issue in the Dependabot auto-merge workflow, and all five action references are unpinned. There are no untrusted checkouts or script injections, which limits the risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 days ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform