Package Health

kero/typesafe-env

The package includes a README, repository tests, release notes, and a source repository that clearly matches it. MIT licensing, no install scripts, read-only workflow permissions, and Dependabot are reassuring, but unpinned actions and no security policy leave maintenance hygiene gaps.

Latest 0.1.3PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Project backingcaution

The package and repository are backed by the same individual account rather than an organization, so the single registry maintainer reflects a genuinely thin ownership base. This is consistent with the small project's scope but limits continuity if that maintainer stops contributing.

Release historycaution

The package has had no registry release in about 17 months, and no releases in the last 12 months, which lowers confidence in ongoing maintenance. Its seven releases since October 2023 show that it is not entirely abandoned.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful sign of currently limited maintenance activity. The recent repository push and release history provide some counterweight but do not show active recent development.

Security policycaution

No security policy is present in the repository, leaving the process for reporting vulnerabilities unclear. The package's small scope and Dependabot reduce, but do not remove, this transparency gap.

Workflow auditcaution

Both workflows use read-only permissions and the audit found no untrusted checkouts, script injection, or other findings, which is reassuring. However, all 8 analyzed action references are unpinned, leaving avoidable action-supply-chain exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Martin Rehberger

Direct Dependencies

DependencyLast ReleaseScore
vlucas/phpdotenv
Version ^5.5
illuminate/support
Version ^10.0 || ^11.0 || ^12.0
phpoption/phpoption
Version ^1.9

Weekly Downloads

Info

Last Published
1 year ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform