Package Health

plotdesk/plugin-sdk

The organization-owned repository is active and not archived, while the small dependency surface keeps integration straightforward. The limited release history, single recent contributor, proprietary license, and missing security policy leave important adoption risks.

Latest v1.0.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensedanger

The manifest declares a proprietary license, with no detected license text or license file in the package or repository. That creates a material legal and transparency concern for an open-source dependency.

Release historycaution

This is the only release in 158 days, so there is little release history to establish maturity or long-term maintenance patterns. The project is still relatively new rather than demonstrably abandoned.

Repo bus factorcaution

One contributor made all commits in the last 3 months, concentrating maintenance responsibility. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced.

Repo commit activitycaution

The repository recorded one commit in the last 3 months, showing some recent activity but very limited evidence of sustained maintenance.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though it is less severe than abandonment or deprecation evidence.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 months ago
Created
5 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform