Package Health

microweber-deps/filament-translate-field

The package is licensed, documented, tested in its repository, and backed by an organization. Its maintenance record is thin, while workflow checks show a high-confidence bot-condition issue and all 10 actions are unpinned.

Latest 1.0PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

There has been only one release, published about 14 months ago, with no releases in the last 12 months. That leaves little evidence of continued release maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one release, this is meaningful evidence of stalled maintenance.

Repository archivedcaution

The repository is not archived, so it remains open to maintenance. Its last push was about 14 months ago, consistent with the separate evidence of limited recent activity.

Security policycaution

No security policy was found in the repository. This is a transparency and incident-handling gap, though it is not by itself evidence that the package is unsafe.

Workflow auditcaution

The audit analyzed all four workflows, but all 10 action references are unpinned, and one high-confidence bot-conditions finding may allow actor context to be spoofed. Three workflows also grant top-level write permissions; with no untrusted checkout or script-injection findings, this remains a workflow-hygiene concern rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Carly

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform