Package Health

lilac-wysiwyg/lilac

The repository is active, has tests, and this release includes specific notes about its packaging fix. Its main weaknesses are the package's same-day release history and workflows that leave all 16 actions unpinned, with one workflow granting broad write access.

Latest v0.7.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package is brand new, with only two releases published on the same day, so there is little evidence of long-term maintenance or release discipline.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a modest transparency gap for a library.

Version stabilitycaution

Version v0.7.1 is not a stable major release, which is reasonable for an early project but signals that its API and behavior may still change.

Workflow auditcaution

All 16 analyzed action references are unpinned, and one workflow uses top-level write permissions. The audit also found high-severity but low-confidence cache warnings and several high-confidence ad hoc package installs, so workflow hygiene is a real caution rather than a severe standalone risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Maifee Ul Asad

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
3 days ago
Created
3 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform