Package Health

flectar/waterhole-turnstile

Usable with caveats: the package is clearly licensed, narrowly scoped, and backed by a matching organization repository, but it has had no commits for about seven and a half months after only two releases. Its tiny codebase and lack of tests or security tooling make ongoing maintenance harder to assess.

Latest 0.2.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, following no newer activity since the January release; this is the strongest maintenance concern.

Maintainerscaution

A single registry publisher is a limited publishing base, but the repository is owned by the backing Flectar organization, which provides some compensation.

Release historycaution

Only two releases have been published, with the latest about seven and a half months ago; this is limited maturity for a dependency, although the package is still relatively young.

Repo issue activitycaution

There are no open issues and one open pull request, but no issues or pull requests were merged in the last month, offering little evidence of active maintenance.

Repo popularitycaution

The repository has only 1 star and 1 fork, indicating limited external adoption; popularity is supporting evidence rather than a decisive health measure for a small extension.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Flectar

Direct Dependencies

DependencyLast ReleaseScore
waterhole/core
Version ^0.6.0

Weekly Downloads

Info

Last Published
7 months ago
Created
8 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform