Package Health

ereborcodeforge/durin-installer

The project is very new, so its rapid initial releases do not yet demonstrate sustained maintenance. Tests, documentation, licensing, organization backing, and read-only workflow permissions are reassuring, but the repository has no security policy and all three workflow actions are unpinned.

Latest v0.2.2PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is only 0 days old with six releases clustered within about 5 hours, showing active initial work but no evidence of a sustained release history.

Repo commit activitycaution

The repository records zero commits and zero active maintainers over the last 3 months. Because the project is newly published, this is mainly a lack of demonstrated history rather than proof of abandonment, but it limits confidence.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a security-maintenance gap for a package that orchestrates project creation.

Security policycaution

The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.

Version stabilitycaution

Version v0.2.2 is not a stable major release, so consumers should expect a less mature API and possible compatibility changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Thales Ruppenthal

Direct Dependencies

DependencyLast ReleaseScore
ereborcodeforge/durin-presets
Version ^0.2.1
—
—

Weekly Downloads

Info

Last Published
5 hours ago
Created
11 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform