Package Health

lenorix/ai

The repository includes tests, a changelog, dependency scanning, and organization backing. However, the package has had no registry releases in 487 days, no recorded commits in three months, and workflow controls need attention.

Latest v0.1.15PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

The package is 487 days old but has had no releases in the last 12 months; its 16 releases were concentrated in a short initial period, which raises abandonment risk.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last three months, despite the repository remaining available; this is a meaningful sign of slowing maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations less transparent for adopters.

Version stabilitycaution

Version v0.1.15 is not a stable major release, so compatibility expectations are limited, although it is not marked as a prerelease.

Workflow auditcaution

All 9 action references are unpinned, three workflows grant top-level write access, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so these are workflow-hygiene concerns rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jesus Hernandez

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
guzzlehttp/guzzle
Version ^7.9
—
—
swaggest/json-schema
Version ^0.12.43
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform