Package Health

micro-module/saga-bundle

The repository contains tests and the release uses no install-time scripts, reducing operational risk. No security scanning or security policy is present; confirm permitted use and provenance before adopting it.

Latest v0.6.3PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

56

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Licensedanger

The manifest declares the package proprietary, with no detected license text or license file. That creates a significant legal barrier for a dependency described as open source.

Package scaffoldingcaution

The package includes tests and the repository includes tests, which supports basic project maturity. The missing package README is a minor consumer-documentation gap for a library.

Release historycaution

The package has existed for about 6 years 5 months but has only 8 releases, with a median interval of about 279 days and one release in the last 12 months. This indicates a slow maintenance cadence, although a recent release exists.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the last 3 months. The release was published recently, but the lack of observed ongoing activity raises maintenance risk.

Repo package mentioncaution

The repository name does not match the package name, and no README mention was available. The mismatch may be normal for a sub-package, but the missing corroboration weakens provenance confidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
micro-module/saga
Version ^0.6.0 || ^0.7

Weekly Downloads

Info

Last Published
5 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform