Package Health

jakuborava/weight

It has a clear MIT license, a matching repository, tests, and a minimal dependency footprint. Workflow checks also contain two high-confidence hygiene issues, so maintenance and build trust need attention.

Latest 1.1.1PackagistPackagist

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has had no release in about four years and has no releases in the last 12 months, indicating substantial abandonment risk despite its three-release history.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, reinforcing the concern that development has stalled.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap for a package with no recent activity.

Workflow auditcaution

All four workflows were analyzed, but the audit found high-confidence bot-condition and unpinned-image issues; all eight action references are also unpinned, weakening build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jakub Orava

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform