Package Health

fond-of-oryx/one-time-password-extension

The MIT license, tests, and matching organization repository improve transparency. Unpinned workflow actions and no security policy add maintenance risk, leaving this release a weaker long-term dependency choice.

Latest 2.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has only two releases, with the latest released nearly 4 years ago and no releases in the last 12 months. This is meaningful evidence of limited ongoing maintenance.

Repo commit activitycaution

There were no commits and no active maintainers in the last 3 months, consistent with a repository that has seen little recent development. Combined with the old latest release, this raises abandonment risk.

Repo popularitycaution

The repository has zero stars and forks and only one watcher, providing little supporting evidence of broad community review or adoption. Popularity is secondary evidence, but it reinforces the thin maintenance picture.

Repo toolingcaution

The repository uses Make and Composer, but no security scanning tools were detected. For a small package this is a hygiene gap rather than a severe risk.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, not evidence of malicious behavior.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Julian Hyatt

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform