Package Health

oat-sa/lib-lti1p3-deep-linking

Documentation and testing are solid, with organization backing and security scanning in place. The limited recent activity and workflow pinning leave more maintenance and build-integrity risk than a fully healthy dependency.

Latest 4.1.2PackagistPackagist

67%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has 8 releases since October 2020, but none in the last 12 months; the latest registry release is over a year old. This is a meaningful maintenance concern despite the package's established history.

Repo bus factorcaution

All recent commits came from one contributor, giving the project a high short-term bus-factor risk. Organization ownership provides some handoff capacity, but no second recent contributor is shown.

Repo commit activitycaution

Only 1 commit from 1 active maintainer was recorded in the last 3 months. That is weak current activity and raises abandonment risk, even though the repository is not archived.

Security policycaution

The repository has no security policy. For a library handling LTI security workflows, this is a transparency and response-process gap.

Workflow auditcaution

Both workflows were analyzed without high-confidence findings or untrusted triggers, but all 6 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain controls, so this is a hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
oat-sa/lib-lti1p3-core
Version ^7.0
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform