Package Health

omerkoseoglu/devextreme-data

The package is clearly licensed, documented, tested in the repository, and matched to its source repository. Its CI workflow is fully analyzed and has no detected dangerous findings, but external actions are unpinned and security scanning is absent.

Latest v0.1.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

This is the package's first release, published today, so there is no release track record yet. That limits confidence about sustained maintenance but does not indicate abandonment on its own.

Repo commit activitycaution

No commits or active maintainers were observed during the last three months, but the repository and release are only hours old. This is an important coverage limitation rather than evidence of a collapsed project.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap for a package intended to process application data, though it is not evidence of unsafe code.

Version stabilitycaution

Version v0.1.0 is an early non-stable-major release, which signals limited maturity and possible API change risk. It is not marked as a prerelease, providing a small counterpoint.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous audit findings or untrusted checkout and script-injection paths. Both external action references are unpinned, leaving a modest supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 hour ago
Created
1 hour ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform