Package Health

nystudio107/craft-vite

The MIT license, release notes, and matching source make the package transparent to adopt. Organization ownership and a non-archived repository help offset the narrow recent contributor base; workflow references are all unpinned.

Latest 5.0.2PackagistPackagist

70%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Repo bus factorcaution

All two recent commits came from one contributor, giving the project a narrow current contributor base and increasing continuity risk if that contributor becomes unavailable.

Repo commit activitycaution

Only two commits were recorded in the last three months, indicating limited recent development activity despite the recent release.

Workflow auditcaution

All three workflows were analyzed without high- or medium-severity findings, and permissions are not broadly write-enabled. However, all seven action references are unpinned, leaving avoidable build reproducibility and action-change exposure.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

nystudio107

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^5.0.0
nystudio107/craft-plugin-vite
Version ^5.0.3

Weekly Downloads

Info

Last Published
1 month ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform