Package Health

phrozenbyte/pico-deprecated

The MIT license, clear README, and changelog make its contents easy to inspect. A missing security policy, no security scanning, and unpinned workflow actions leave less evidence for ongoing care.

Latest v3.0.0PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historycaution

All 18 releases were published within one day, with no later release activity across roughly nine months. That pattern suggests a one-time repackaging or migration rather than sustained maintenance.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, despite being assessed about nine months after its last push. For a compatibility plugin, that is meaningful abandonment risk.

Repo toolingcaution

The repository uses Make and Composer, showing a defined build path, but no security-scanning tool was detected. This weakens ongoing maintenance transparency without proving the release is unsafe.

Security policycaution

No security policy was found in the repository. That leaves contributors and users without a documented vulnerability-reporting process.

Workflow auditcaution

All four analyzed action references are unpinned, which weakens workflow reproducibility. The reported cache-poisoning finding has low confidence and is hygiene rather than a severe risk on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Daniel Rudolf
The Pico Community
Contributors

Direct Dependencies

DependencyLast ReleaseScore
phrozenbyte/pico
Version self.version
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform