Package Health

mortenscheel/task-flow

The package has a clear README, tests, release notes, and an MIT license, which support adoption. Its workflows are auditable but use six unpinned actions, and no security policy or scanning tool is present.

Latest 0.2.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

63

Health Score Breakdown

Release historydanger

Only two releases exist, both published in December 2024, with no release in roughly one year and nine months. That limited and inactive history lowers confidence in ongoing maintenance.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers over the last three months. Combined with the old last release, this is strong evidence that maintenance has stalled.

Lifecycle scriptscaution

The package defines a post-create-project-cmd lifecycle script. This adds installation-time behavior that deserves review, though the signal does not show a dangerous command or broad install hook.

Project backingcaution

The package and repository are consistently owned by the same individual account, so the source relationship is clear. Individual ownership also indicates a relatively narrow maintenance base.

Repo issue activitycaution

There are two open issues and no issue or pull-request activity in the last month. This is limited evidence of current project attention, though the issue count is small.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Morten Scheel

Direct Dependencies

DependencyLast ReleaseScore
symfony/console
Version ^7.2

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform