Package Health

milpa/live-tui

This release presents a generally healthy dependency profile: it is not deprecated or archived, was pushed very recently, includes substantial documentation, tests, changelog, licensing, security-policy documentation, and safe workflow analysis, and its repository clearly matches the package. The main concerns are that the package is young at 42 days, remains pre-1.0, has only one active contributor responsible for all 32 recent commits, lacks configured security-scanning tools, and uses top-level write permissions in three workflows. The organization backing and active release/merge cadence reduce—but do not eliminate—the single-maintainer and maturity risks.

Latest v0.9.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

80

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access, which is a modest release-continuity concern; the linked repository is organization-owned, providing some backing beyond the registry access list.

Release historycaution

Seventeen releases in 42 days, with a median interval of about 22 hours, show strong current activity, though the short project age means long-term maintenance is not yet demonstrated.

Repo bus factorcaution

All 32 recent commits were made by one contributor, creating a real continuity risk; organization ownership provides some potential for handoff, but no second active contributor is shown.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This offers no supporting adoption evidence, but popularity is not decisive for a young, specialized package.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool is configured, leaving a security-process gap despite otherwise established build infrastructure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodrigo Vicente - TeamX Agency

Direct Dependencies

DependencyLast ReleaseScore
milpa/core
Version >=0.6.2 <1.0
—
—
milpa/live
Version >=0.4 <1.0
—
—

Weekly Downloads

Info

Last Published
18 days ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform