Package Health

jazzsequence/jazzs3quence-priority-manager-for-ai-connectors

Healthy and actively maintained, with clear packaging, tests, and recent releases. The main caveat is that all recent commits come from one contributor and the repository lacks a security policy and explicit workflow permissions.

Latest 1.3.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publishing access. Because the repository is owned by the same individual rather than an organization, this leaves limited publishing redundancy, although repository activity shows the maintainer is active.

Repo bus factorcaution

One contributor made 100% of the 16 commits in the last three months. This creates a genuine continuity risk for an individually owned project.

Repo popularitycaution

The repository has one star and no forks or watchers. This is weak supporting evidence, but popularity alone does not outweigh the active release and commit signals.

Security policycaution

The repository has no security policy. For a plugin handling AI-provider configuration, this is a transparency and vulnerability-reporting gap, though the repository does use automated security scanning.

Token permissionscaution

All four workflows lack top-level token permissions, and none declares read-only permissions. Although no workflow requests top-level write access, explicit least-privilege declarations would provide better supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Chris Reynolds

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
20 days ago
Created
4 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform