Package Health

henriquebs0/automaton

The MIT license and direct repository match make its provenance clear. Its six-file library has almost no documentation, no tests, and no security policy, leaving little evidence of maintenance quality. Pinning this version means accepting a long-unmaintained dependency.

Latest 1.0.0PackagistPackagist

42%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

67

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

This is the package's only release, published about four years ago, with no releases in the last 12 months. That long silence is strong evidence of abandonment risk.

Package scaffoldingcaution

The package includes a README, but it is only 12 characters long and provides no meaningful usage guidance. The absence of tests and a changelog is normal for published artifacts and is not counted against it.

Repo toolingcaution

Composer is used for the build, but no security-scanning tooling is present. This weakens supply-chain hygiene, though it is less significant than the package's prolonged inactivity.

Security policycaution

The repository has no security policy, reducing transparency for reporting and handling issues. This is a secondary concern for a small package, but no provided signal compensates for it.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

HenriqueBS0

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform