Package Health

prinsfrank/glyph-lists

Usable with caveats: this is a small, clearly licensed PHP data package with tests, release notes, minimal runtime dependencies, and no install scripts. However, it has had only one release and no repository commits or active maintainers in the last three months, so ongoing maintenance is uncertain.

Latest v1.0.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Release historycaution

There has been only one release, published about 12 months ago, so there is little release history to demonstrate sustained maintenance. For a static glyph-list package this may be adequate, but it leaves long-term upkeep uncertain.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers in the last three months, roughly a year after its only release. Static data may require few changes, but this is the main evidence of uncertain ongoing maintenance.

Security policycaution

No security policy is present. This is a transparency gap, though the package is a small static data library with minimal runtime dependencies and no reported dangerous workflow patterns.

Token permissionscaution

The only workflow lacks top-level token permissions, so its effective permissions are not explicitly minimized in the workflow file. No top-level write permissions were observed, making this a minor workflow-hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform