Package Health

hongyi/bucket

Its 12-character README, absent tests, and missing security policy leave little consumer or maintenance transparency. MIT licensing and a clean workflow audit help, but one workflow uses an unpinned action with broad write permissions.

Latest 1.0.3PackagistPackagist

44%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package is about 416 days old but has only three releases, all within the first few weeks, and no releases in the last 12 months. This suggests activity stopped soon after initial publication.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with more than a year without observed updates. That materially increases abandonment risk.

Package scaffoldingcaution

The package includes a README, but it is only 12 characters long, providing almost no integration guidance. Missing tests and a changelog are normal for published artifacts and are not concerns here.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. This weakens confidence that the linked source repository directly belongs to this release.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no community signal to offset the inactivity concerns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

zhubaiming

Direct Dependencies

DependencyLast ReleaseScore
hongyi/designer
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform