Package Health

millipress/millibase

MilliBase v2.11.0 appears to be a healthy, actively maintained dependency: it has 39 releases over 182 days, frequent recent publishing, a stable non-prerelease version, an active non-archived organization-owned repository, 73 commits in the last 3 months, and 8 merged pull requests in the last month. The repository provides tests and a changelog even though they are not included in the artifact, and it uses Composer plus Dependabot. The main reservations are the highly concentrated commit activity, install/update lifecycle scripts, absent security policy, and write-scoped workflow permissions; these warrant review but do not outweigh the strong maintenance and release evidence.

Latest v2.11.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

70

Health Score Breakdown

Lifecycle scriptscaution

The package declares post-install-cmd and post-update-cmd scripts, which increase installation-time execution surface and merit review before adoption.

Repo bus factorcaution

Two contributors were active, but one authored about 97.3% of the 73 recent commits, creating a concentrated maintenance risk; organization ownership partly compensates through potential handoff capacity.

Repo popularitycaution

The repository has 1 star and no forks or watchers. This is limited adoption evidence, but popularity is supporting evidence and does not outweigh the observed maintenance activity.

Security policycaution

No repository security policy was found, leaving vulnerability-reporting and response guidance less transparent.

Token permissionscaution

All workflows declare top-level permissions, but two have write permissions while only one is read-only; this increases CI credential impact if a workflow is compromised.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Philipp Wellmer

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
12 days ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform