Package Health

infrajs/ascroll

The small package has a clear source match, a usable README, stable versioning, and no install-time scripts. Its single registry maintainer, absent license, and lack of security scanning reduce transparency and resilience despite organization backing.

Latest v1.0.32PackagistPackagist

56%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

No declared license, license file, or repository license file was detected. This creates a material legal and transparency gap for dependency use.

Maintainerscaution

Only one registry account has publish access, which creates a limited publishing safety net. The organization-backed repository provides some compensation, so this is a moderate concern rather than a severe one.

Release historycaution

The package has 32 releases since November 2015, but its latest release was in September 2021 and there have been no releases in roughly five years. This is a meaningful maintenance concern, though the stable release history shows it was previously established.

Repo commit activitycaution

The repository recorded no commits and no active maintainers in the last three months. Combined with the old last push, this indicates prolonged inactivity and raises abandonment risk.

Repo toolingcaution

Composer is used as a build tool, showing basic ecosystem integration, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than proof of unsafe code.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform