Package Health

milon/jigsaw-url-shortener

This release appears usable and reasonably transparent: it has an MIT license, a matching repository with tests, a small and focused dependency profile, no install-time lifecycle scripts, stable versioning, and no registry deprecation or archive status. The main concerns are limited release history, a single registry maintainer, very low repository adoption, no recent recorded commit activity despite the latest release, absent security-policy documentation, and a release workflow with top-level write permissions. These issues suggest a small, lightly maintained project rather than an immediately unsafe dependency, so adoption is reasonable with normal maintenance and update review.

Latest v1.1.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Maintainerscaution

A single registry maintainer creates a thin publishing base and increases continuity risk, although this can be normal for a small user-owned project.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-maintainer and low-activity signals represent genuine continuity limitations rather than normal organization publishing structure.

Release historycaution

Only two releases over about 768 days, with one release in the last 12 months, indicates a small and infrequently released project; the recent latest release partly offsets abandonment concerns.

Repo commit activitycaution

No commits and no active maintainers were recorded in the last three months, a meaningful maintenance concern despite the recent repository push and release.

Repo popularitycaution

One star, zero forks, and one watcher show very limited external adoption; this is supporting caution about maturity but is not decisive on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nuruzzaman Milon

Direct Dependencies

DependencyLast ReleaseScore
tightenco/jigsaw
Version ^1.7

Weekly Downloads

Info

Last Published
10 days ago
Created
2 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform