Package Health

natilosir/telegram-bot-sdk

The README and exact-version release notes make the package easier to understand and adopt. MIT licensing and recent releases help, but the project still lacks visible security tooling and has a very small maintenance base.

Latest 1.4.1PackagistPackagist

64%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

The package runs a post-autoload-dump script during installation, adding execution during dependency setup and therefore a modest supply-chain hygiene concern.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.

Release historycaution

The package is only 22 days old but has four releases, with a median interval of about 7 days; this shows active early development without yet demonstrating long-term continuity.

Repo bus factorcaution

One contributor made 100% of the two recent commits, leaving no demonstrated handoff capacity if that maintainer becomes unavailable.

Repo commit activitycaution

Only two commits were recorded in the last three months, all from one active maintainer. The recent push is encouraging, but the small volume limits evidence of sustained maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Natilos.ir

Direct Dependencies

DependencyLast ReleaseScore
natilosir/bot
Version *
natilosir/verta
Version *

Weekly Downloads

Info

Last Published
16 hours ago
Created
23 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform