Package Health

osynapsy/osynapsy-html-bcl

This release appears usable and currently maintained, with a non-archived repository, a push within the assessment period, seven commits in the last three months, tests in both the artifact and repository, a clear MIT license, no deprecation notice, and no install-time lifecycle scripts. Its main weaknesses are a very small release history (three releases over about 3.25 years), a single active contributor responsible for all recent commits, no repository security policy or security-scanning tooling, negligible repository adoption, and a repository/package naming mismatch that warrants verifying the source linkage. Overall, it is a caution-level dependency rather than an obviously abandoned package, but its maintenance continuity and source transparency depend heavily on one individual.

Latest 0.8.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publish access. This is a real continuity concern for a user-owned project because publishing and release authority are concentrated in one person.

Project backingcaution

The linked repository is owned by a user account rather than an organization, so the project does not show organizational backing that would mitigate its concentrated maintenance base.

Release historycaution

The package has only three releases since June 2023, with one release in the last 12 months and a median interval of about 594 days; this indicates limited release maturity and a potentially slow maintenance cadence.

Repo bus factorcaution

All seven recent commits came from a single contributor, producing a high continuity risk if that maintainer becomes unavailable; the repository owner is a user rather than an organization, so there is no provided organizational backing to offset this concentration.

Repo package mentioncaution

The repository name does not exactly match the package name, although the repository file tree contains the package's Osynapsy/Bcl5 source and tests. The mismatch should still be verified because the README mention value is unavailable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Pietro Celeste

Direct Dependencies

DependencyLast ReleaseScore
twbs/bootstrap
Version 5.*
—
—
osynapsy/osynapsy-html2
Version @stable
—
—

Weekly Downloads

Info

Last Published
17 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform