Package Health

noehassiel/confetti

This is a usable but very young package with a coherent 19-file artifact, a README, a stable v1.0.1 release, no deprecation status, minimal runtime dependencies, and recent repository activity. However, it has only two releases over 12 days, all 10 recent commits come from one contributor, there are no tests or changelog, no security scanning or security policy, and the declared proprietary license may restrict adoption or redistribution. The package is not archived and the repository appears to reference the package, so these concerns indicate caution rather than an abandonment verdict.

Latest v1.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Licensecaution

The package declares a proprietary license and includes a LICENSE file, so it is licensed rather than missing licensing information; however, proprietary terms can materially constrain reuse and redistribution by downstream projects.

Maintainerscaution

The registry lists one publishing maintainer. Because the repository is owned by an individual rather than an organization, this represents a genuinely narrow publishing and continuity base.

Package scaffoldingcaution

A substantial README is present and the repository uses GitHub Releases, but neither the artifact nor repository has tests or a changelog. For a new native cross-platform component, the lack of visible tests reduces maintainability and verification confidence.

Project backingcaution

The source repository is owned by an individual user, not an organization, so there is no organizational backing to compensate for the project's narrow contributor base.

Release historycaution

The package is only 12 days old with two releases, both published within roughly an hour, so there is little evidence yet of sustained maintenance or long-term release discipline.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

noehassiel

Direct Dependencies

DependencyLast ReleaseScore
nativephp/mobile
Version ^4.0

Weekly Downloads

Info

Last Published
23 days ago
Created
23 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform