Package Health

julianxhokaxhiu/cyanogenmod-ota

The source is still being updated, with an MIT license, a substantial README, and security scanning in place. Its maintenance depends on one contributor, while the workflow references are unpinned and no security policy is published.

Latest 2.10.0PackagistPackagist

38%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned and names lineage-ota as its replacement. This is a major adoption concern even though the repository remains active.

Repo bus factorcaution

One contributor made all 12 recent commits, leaving no demonstrated backup for ongoing maintenance. The individually maintained project has a concentrated bus factor.

Repo package mentioncaution

The linked repository name does not match the package name and its README does not mention this package. That mismatch makes the package-to-source relationship less transparent, despite the repository appearing related to the same OTA project.

Security policycaution

The repository has no published security policy, so users have no documented channel or process for reporting vulnerabilities. This is a transparency gap for a server package.

Workflow auditcaution

All five analyzed action references are unpinned, which weakens build reproducibility and lets referenced action code change without a reviewed version. The audit found no dangerous triggers, sinks, or high-confidence workflow findings.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Julian Xhokaxhiu

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version 3.*
—
—
mikecao/flight
Version 2.*
—
—
julianxhokaxhiu/dotnotation
Version dev-master
—
—

Weekly Downloads

Info

Last Published
2 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform