Package Health

nguyenanhung/dotenv

The package includes a README, tests, changelog, MIT license, and a clean workflow audit. Maintenance is a concern because it has had no release or commit activity for roughly two years, with no security policy and all workflow actions unpinned.

Latest v1.0.2PackagistPackagist

57%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly two-year gap since the latest release and raising abandonment concerns.

Release historycaution

The package has only three releases since June 2022 and none in the last 12 months; its latest release was in September 2024, indicating a slow and now inactive release cadence.

Repo popularitycaution

The repository has 0 stars and 0 forks, with only 2 watchers. Popularity is supporting evidence rather than a verdict, but these numbers provide little evidence of a broad user or contributor base.

Security policycaution

The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities; no other provided signal compensates for that gap.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 3 action references are unpinned, leaving a modest reproducibility and workflow supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Nguyen An Hung

Direct Dependencies

DependencyLast ReleaseScore
vlucas/phpdotenv
Version ^5.0 || ^4.0
—
—

Weekly Downloads

Info

Last Published
2 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform