Package Health

pecotamic/redirect

This is a generally healthy, actively published package with a stable 2.0 release, a repository that is not archived, matching package documentation, comprehensive tests, a small dependency footprint, and no install-time lifecycle scripts. The main concerns are the absence of any license declaration or license file, no commits or active maintainers in the last 3 months despite a recent release, and modest repository security-process hygiene: no security policy and no top-level workflow permissions. These issues warrant review before adoption, but the organization-backed repository, recent release cadence, test coverage, build tooling, and safe workflow analysis provide substantial compensating evidence.

Latest 2.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Licensecaution

Neither a declared license nor a license file was found in the artifact or repository. This is a genuine transparency and usage-risk gap for a dependency.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the release was published recently, the lack of recent commit activity is a maintenance concern and lowers confidence in ongoing development capacity.

Security policycaution

No repository security policy was found. This is a modest transparency and vulnerability-reporting gap, though it is less severe for a small package with security scanning enabled.

Token permissionscaution

The only workflow lacks top-level token permissions, but it declares no top-level write permissions. The configuration is less explicit than a read-only policy and merits caution, without evidence of excessive token authority.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
statamic/cms
Version ^5.0|^6.0

Weekly Downloads

Info

Last Published
10 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform