Package Health

qqzeng/qzdb

The repository has no security policy, and all 17 workflow actions are unpinned; a low-confidence cache-poisoning alert adds hygiene risk. Two active contributors and a substantial README provide useful support.

Latest 1.2.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Maintainerscaution

A single registry publishing maintainer is a modest publishing-capacity concern, though repository activity provides additional support.

Project backingcaution

The repository is owned by an individual rather than an organization, so the concentrated contributor activity is less easily offset by formal project backing.

Release historycaution

The package is only 20 days old with three releases, so its maintenance record is still limited despite a recent release every roughly 10 days.

Repo bus factorcaution

Two contributors were active, but one accounts for 80% of recent commits, leaving maintenance somewhat concentrated.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

qqzeng

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 days ago
Created
22 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform