Package Health

jonnitto/iframe

jonnitto/iframe 5.0.0 is a small, long-established and currently usable package: it has existed for over 10 years, has a stable major release, is not deprecated, has a matching source repository that mentions the package, and was recently published. The main concerns are that only one maintainer is listed, repository popularity is very low, there were no commits or active maintainers in the last 3 months, and the project has no tests, security policy, or security-scanning tooling. These issues warrant monitoring and may increase bus-factor and maintenance risk, but the active, non-archived repository and recent release keep it in the caution rather than unhealthy range.

Latest 5.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account, Jon Uhlmann, has publishing access. This creates a meaningful publishing bus-factor concern, although the linked repository is also owned by that individual and recent release activity provides some compensation.

Package scaffoldingcaution

A README and GitHub Releases are present, but neither the artifact nor repository contains tests or a changelog. The missing tests and changelog reduce transparency somewhat, although the README documents installation and use.

Project backingcaution

The repository is owned by an individual account rather than an organization, so there is no organizational backing to reduce the single-owner risk. However, the repository owner is consistent with the package publisher context.

Repo commit activitycaution

There were zero commits and zero active maintainers in the last 3 months, which is a concrete maintenance-cadence concern. The recently pushed repository and newly released version partly offset this, but do not demonstrate sustained ongoing development.

Repo popularitycaution

The repository has 1 star, 0 forks, and 1 watcher. This indicates very limited community adoption or visibility, but popularity is supporting evidence rather than a standalone health verdict.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jon Uhlmann

Direct Dependencies

DependencyLast ReleaseScore
neos/neos
Version ^8.4 || ^9.0
—
—
carbon/eel
Version ^2.28
—
—
carbon/notification
Version ^2.4 || ^3.0
—
—

Weekly Downloads

Info

Last Published
15 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform