Package Health

milpa/workflow

This is a well-documented, actively developed young package with strong artifact and repository hygiene: it has a license and NOTICE files, tests, a changelog, CI workflows, a security policy, recent releases, and no deprecation or archive indicators. The main concerns are its short 60-day history, pre-1.0 versioning, and substantial maintainer concentration: all 14 recent commits came from one contributor, despite organization ownership providing some handoff capacity. The repository also lacks automated security-scanning tools and grants top-level write permissions to three workflows, which warrants review of the release and documentation automation before adoption. Overall, it appears usable and transparently maintained, but it has not yet demonstrated long-term stability or a broad maintenance base.

Latest v0.1.6PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Release historycaution

Seven releases in the first 60 days, with a median interval of about 2 days, demonstrates active publishing, although the short history does not yet establish long-term maintenance.

Repo bus factorcaution

One contributor made all 14 commits in the last three months, creating a real continuity risk; organization ownership partially compensates because maintenance can potentially be handed off within the organization.

Repo popularitycaution

The repository has zero stars, forks, and watchers. This limits external validation, but popularity is supporting evidence and the package's direct maintenance signals are stronger than this absence.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap, though the repository's security policy and workflow-risk results provide partial compensation.

Token permissionscaution

All workflows declare permissions, but three workflows grant top-level write access. Explicit permissions are better than undeclared defaults, yet broad write capability increases the impact of workflow compromise and merits review.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rodrigo Vicente - TeamX Agency

Direct Dependencies

DependencyLast ReleaseScore
milpa/core
Version >=0.6.2 <1.0
—
—
doctrine/orm
Version ^3.0
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform