Package Health

prettysmilefordevil/dadata

The package includes substantial documentation, tests, a changelog, and a simple dependency profile. It lacks a security policy and scanning, so future maintenance and vulnerability response are uncertain.

Latest 1.0.0PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

38

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

78

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Release historydanger

This is a single-release package, with no releases in roughly 3 years and 10 months. That strongly limits evidence of ongoing maintenance, although the repository is not archived and the release is not deprecated.

Repo commit activitydanger

There were zero commits and zero active maintainers in the last 3 months. Combined with the last push in November 2022, this is strong evidence that maintenance has stopped.

Maintainerscaution

Only one registry maintainer entry is listed, which leaves limited visible publishing redundancy. The repository's tests and documentation provide some compensation, but not evidence of a broader active maintainer base.

Project backingcaution

The repository is owned by an individual user rather than an organization, so the single registry maintainer entry has no visible organizational backing to compensate for the inactive project.

Repo issue activitycaution

There were no new or merged pull requests and no issue activity in the last month. This is consistent with an inactive project, though the open-issues count is unknown.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

HFLabs and contributors

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ~6.0|^7.0
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform