Package Health

lion/helpers

lion/helpers v6.1.5 appears suitable to depend on: it has a long release history with 34 releases, seven releases in the last 12 months, a stable non-prerelease version, current repository activity, tests, changelog, licensing, and a small runtime dependency surface. The main concerns are that recent repository work is concentrated in one contributor, the repository has very limited external popularity, no security policy, and its workflow lacks a top-level token-permissions declaration; these are meaningful hygiene and resilience gaps but are partly offset by organization backing, Dependabot, safe workflow findings, and continued releases. Overall, this is a healthy package with moderate bus-factor and repository-security caveats.

Latest v6.1.5PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a modest publishing-resilience concern, though the linked repository is owned by an organization and recent activity demonstrates ongoing maintenance.

Repo bus factorcaution

All recent commits came from one contributor, creating a concentrated bus factor. Organization ownership provides some capacity for handoff, but no second active contributor is shown.

Repo commit activitycaution

There was one commit by one active maintainer in the last three months. Recent releases and merged pull requests show activity, but the low commit volume warrants some caution about maintenance depth.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little external adoption or review signal.

Security policycaution

No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
24 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform