Package Health

helsingborg-stad/modularity-recommend

This is a usable, transparently linked package with a stable release, regular release history, active organizational backing, a matching repository, modest runtime dependency surface, and no deprecation or dangerous workflow findings. However, recent repository commit activity is absent, the package and repository report no tests, the artifact lacks a README and changelog, the repository has no security policy, and workflow token permissions are not consistently declared. These are meaningful maintenance and hygiene concerns, so the package falls in the caution band rather than the healthy band, despite its continued releases and recent repository push.

Latest 4.2.4PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a continuity concern in isolation. The repository is owned by an organization, making a short registry maintainer list more understandable, but it still leaves publishing operations dependent on a narrow account base.

Package scaffoldingcaution

The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. GitHub Releases provide some release communication, but the absence of tests and basic documentation remains a maintenance and transparency gap.

Repo commit activitycaution

The repository reports 0 commits and 0 active maintainers in the last 3 months, which is a significant maintenance concern. The recent push and continued registry releases provide some compensation, but they do not demonstrate sustained source-level development activity.

Repo popularitycaution

The repository has 0 stars, 2 forks, and 4 watchers, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a verdict, so this is only a mild concern for ecosystem validation.

Security policycaution

No repository security policy was found. This is a transparency and vulnerability-reporting gap, though the presence of Sonar and GitGuardian scanning provides partial compensating security practice.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sebastian Thulin

Direct Dependencies

DependencyLast ReleaseScore
helsingborg-stad/wpservice
Version ^2.0
helsingborg-stad/wputilservice
Version ^0.3

Weekly Downloads

Info

Last Published
11 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform