Package Health

fond-of-kudu/jellyfish-kletties

The package is MIT-licensed, tested, and tied to an organization-owned repository. Its only release was 752 days ago, recent commit activity is absent, and the workflow leaves all three actions unpinned without security scanning or a security policy.

Latest 1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

This is the sole release, published 752 days ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance, although the repository was pushed later and is not archived.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months. This supports an abandonment concern, though the package may be intentionally stable.

Repo toolingcaution

The repository uses Make and Composer, showing basic build tooling, but no security scanning tools were detected. That is a transparency and maintenance weakness.

Security policycaution

No security policy was found in the repository. This is a minor transparency gap, especially alongside the absence of security scanning.

Workflow auditcaution

All three analyzed action references are unpinned, weakening build reproducibility and update safety. The audit was complete and found no untrusted checkout, injection, or high-severity workflow issue; the missing top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pascal Fischer

Direct Dependencies

DependencyLast ReleaseScore
fond-of-kudu/kletties
Version ^1.0.0
—
—
fond-of-oryx/jellyfish-sales-order-extension
Version ^1.0.0 || ^2.0.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform