Package Health

glueful/aegis

Aegis v1.16.0 appears healthy and reasonably mature for adoption: it has a stable release, 27 releases over about 358 days with 26 in the last 12 months, recent repository activity, substantial tests and documentation, a matching source repository, and no deprecation or install-time lifecycle scripts. The main concerns are that all 29 commits in the last 3 months came from one contributor, the repository has minimal observed popularity, and no security policy or security-scanning tooling is present; these are meaningful transparency and resilience gaps but are partly offset by organization ownership, ongoing releases, and strong package scaffolding.

Latest v1.16.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo bus factorcaution

One contributor made all 29 commits in the last 3 months, creating a real continuity and bus-factor concern. Organization ownership provides some potential handoff capacity, but no second active contributor is evidenced.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 0 watchers, providing little external adoption evidence; this is a supporting caution rather than a decisive health issue.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are detected; for an RBAC package, the missing security automation is a meaningful hygiene gap.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and disclosure procedures undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Glueful Team

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
19 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform