Package Health

dovstone/quant

This is a usable but very new v1.0.0 package with a clean MIT license, a matching repository, minimal runtime dependencies, and no install-time or workflow risks. However, it has only one release and is 0 days old, with no observed commits or active maintainers over the measured three-month window, no tests or changelog, no security policy or security scanning, and a single individual with registry publishing access. These gaps may partly reflect the package's immediate launch, but they leave maintenance maturity and long-term support largely unproven, so adoption carries moderate dependency risk.

Latest v1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account, Dov Stone, has registry publish access. The linked project is user-owned, so there is no organizational backing shown to compensate for this narrow maintainer base.

Package scaffoldingcaution

A substantial README is present, but neither the artifact nor repository contains tests or a changelog. For a database ORM, the absence of visible tests is a meaningful maintenance and regression risk.

Project backingcaution

The source repository is owned by an individual user rather than an organization, providing no organizational continuity signal. This is consistent with the single registry maintainer and leaves bus-factor concerns unresolved.

Release historycaution

There is only one release and the package is 0 days old, so maintenance history, compatibility evolution, and release reliability cannot yet be established.

Repo commit activitycaution

The repository records 0 commits and 0 active maintainers over the measured three-month period. Since the package is only 0 days old, this is primarily a lack of demonstrated history, but it still leaves ongoing maintenance capacity unproven.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Dov Stone

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
16 days ago
Created
16 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform