Package Health

m4v3rick4git/flarum-lineup

The release includes detailed verification notes, a substantial test suite, and a matching source repository. Its short history, single publisher, absent security policy, and unpinned workflow actions leave limited evidence of long-term resilience.

Latest v0.1.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. That is a thin publishing base for a user-owned project and increases continuity risk if that person becomes unavailable.

Release historycaution

The package is only 46 days old with three releases, all within about three days; this shows activity but provides little evidence of long-term maintenance.

Repo toolingcaution

Composer build tooling is present, but no repository security-scanning tool was detected; the release notes report an npm audit result, which provides some compensating evidence but not ongoing repository coverage.

Security policycaution

The repository has no security policy, leaving no documented channel or process for reporting and handling vulnerabilities.

Version stabilitycaution

v0.1.2 is not a stable major release, so its API and behavior may still change materially despite not being marked as a prerelease.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

m4v3rick

Direct Dependencies

DependencyLast ReleaseScore
flarum/core
Version ^1.8
—
—
guzzlehttp/guzzle
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform