Package Health

milpa/ops

milpa/ops v0.3.2 appears usable and well-structured, with a matching repository, Apache-2.0 licensing, tests, changelog, security policy, active release and pull-request activity, and no deprecation or archival indicators. The main reservations are that the package is young at 41 days, remains below a stable major version, and all recent commits come from one contributor; organization backing partly mitigates the bus-factor concern but does not eliminate it. The repository also lacks detected security-scanning tooling and several workflows grant top-level write permissions, which warrants review before adoption. Overall, it is a promising actively developed dependency rather than a mature, low-risk one.

Latest v0.3.2PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

Seven releases in 41 days, with a median interval of about 2.5 days and a release as recently as the assessment date, show strong current activity; the short history still limits maturity evidence.

Repo bus factorcaution

One contributor made all eight recent commits, creating a genuine continuity risk; organization ownership partially compensates because maintenance can potentially be handed off.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This is weak supporting evidence, but popularity is not decisive and the observed development activity is more relevant.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tool was detected. The repository's SECURITY.md and CI workflows provide some compensating hygiene, but not equivalent automated scanning.

Token permissionscaution

All workflows declare permissions, but three grant top-level write permissions while only one is read-only; this expands CI credential scope and merits review, despite the absence of other dangerous workflow patterns.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodrigo Vicente - TeamX Agency

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3

Weekly Downloads

Info

Last Published
14 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform