Package Health

millipress/acorn-millicache

Healthy and suitable to use, with a small maintenance caveat. It has recent releases, matching organization-backed source code, tests, documentation, and active automation; recent repository work is concentrated entirely in one contributor, which increases continuity risk.

Latest v1.3.1PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Repo bus factorcaution

All six recent commits came from one contributor, giving the project a thin active contributor base. Organization backing partly offsets handoff risk, but continuity still depends heavily on one person.

Security policycaution

No repository security policy is present. This is a transparency gap, though the package still has active releases and dependency scanning.

Token permissionscaution

One workflow lacks top-level permissions and another grants top-level write access, leaving workflow privileges broader or less explicit than ideal. The absence of other dangerous workflow patterns provides partial reassurance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Philipp Wellmer

Direct Dependencies

DependencyLast ReleaseScore
roots/acorn
Version ^4.0 || ^5.0 || ^6.0
millipress/millicache
Version ^1.8.1

Weekly Downloads

Info

Last Published
22 days ago
Created
7 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform