Package Health

ghostzero/tmi

The source is small and has no security policy; both workflow actions are unpinned. Recent activity and release notes provide useful maintenance evidence, but one-person ownership limits continuity.

Latest 2.4.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement named. This is a substantial adoption and continuity risk despite other signs of recent work.

Project backingcaution

The registry and repository are owned by the same individual account, confirming a matching source rather than a misleading namespace. It does not provide organizational maintenance redundancy.

Release historycaution

The package has 13 releases over about six years and one release in the last 12 months, indicating a mature but relatively slow cadence. The latest release is recent, which partly offsets the slower pace.

Repo bus factorcaution

All recent commits came from one contributor, so maintenance depends on a single active person. The repository is user-owned rather than organization-backed, providing no shown handoff capacity.

Repo commit activitycaution

The repository had two commits in the last three months and one active maintainer. This is evidence of ongoing work, but the volume is limited.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

René Preuß

Direct Dependencies

DependencyLast ReleaseScore
react/socket
Version ^1.6
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform