Package Health

monad/clarity

Monad Clarity v1.8.0 appears usable and actively maintained, with 12 releases over 44 days, 125 commits from three active contributors in the last three months, 17 merged pull requests in the last month, a non-archived repository, stable semver, documented tests and changelog coverage, and an MIT license. The package is relatively young and has limited adoption, while the repository lacks a security policy, security-scanning tooling, and explicit top-level GitHub Actions token permissions; these are meaningful transparency and hardening gaps but not evidence of abandonment. The single registry maintainer is partly mitigated by organization ownership and active multi-contributor development.

Latest v1.8.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

Twelve releases in 44 days, with a median interval of about 1 day, show strong recent publishing activity; the short 44-day history also means long-term maintenance maturity is not yet established.

Repo popularitycaution

The repository has only 1 star, 0 forks, and 0 watchers, so external adoption and independent validation are limited; this is supporting evidence rather than a standalone health verdict.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools are configured, leaving a security-hygiene gap for a framework with substantial runtime functionality.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and maintainer response procedures.

Token permissionscaution

The sole workflow lacks top-level GitHub Actions token permissions, so least-privilege permissions are not explicitly documented even though no top-level write permission was observed.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Marshal Yung

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
nyholm/psr7
Version ^1.8
ramsey/uuid
Version ^4.9
nesbot/carbon
Version ^3.13
psr/http-client
Version ^1.0

Weekly Downloads

Info

Last Published
11 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform