Package Health

milpa/agent

The package includes tests, a changelog, release notes, a clear license, and a security policy. Its automated workflows use broad write permissions and leave all seven action references unpinned.

Latest v0.49.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

All 105 recent commits came from one contributor, creating a meaningful continuity risk; organization backing partly offsets the lack of contributor diversity.

Repo popularitycaution

The repository has no stars, forks, or watchers, so it has little external adoption evidence; this young package's strong release and commit activity compensates for that limited supporting signal.

Repo toolingcaution

Composer build tooling is present, but no security scanning tool was detected; the repository's separate security policy provides some compensating transparency.

Version stabilitycaution

Version 0.49.0 is not a prerelease, although the package remains below 1.0 and may still undergo breaking changes.

Workflow auditcaution

All four workflows were analyzed successfully with no injection or high-confidence audit findings. However, all seven action references are unpinned and three workflows grant top-level write permissions, creating avoidable maintenance and token-scope risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodrigo Vicente - TeamX Agency

Direct Dependencies

DependencyLast ReleaseScore
milpa/command
Version >=0.25.1 <1.0
milpa/event-store
Version >=0.3 <1.0

Weekly Downloads

Info

Last Published
2 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform