Package Health

pma987/test2

The package is clearly licensed and includes a useful README, but it has no security policy and its repository has little visible adoption. Eight workflow actions are unpinned, adding avoidable build-supply-chain maintenance risk.

Latest 1.2.9PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

75

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The latest release was about 5 years ago, with no releases in the last 12 months. That long release gap is a meaningful abandonment concern despite 25 historical releases.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's roughly 5-year-old release history. This materially lowers confidence in ongoing maintenance.

Repo package mentioncaution

The repository name matches the package, but its README does not mention the package name. This weakens evidence that the source is documented for this package and adds a modest transparency concern.

Security policycaution

The repository has no security policy. For a library handling CA-bundle paths and certificate material, this reduces transparency about reporting and response, with no provided evidence compensating for the gap.

Workflow auditcaution

All 8 analyzed action references are unpinned, while the audit found no untrusted checkouts, script injection, or high-severity findings. The clean audit offsets severe workflow concerns, but unpinned actions remain a maintenance and supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jordi Boggiano

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 years ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform