Package Health

qte-technologies/industrial-scientific-catalog

The repository has 30 commits in the past three months, and the package includes a README, release notes, and no install-time scripts. Its single-contributor base, license mismatch, repository naming gap, and unpinned workflow actions warrant caution.

Latest V07.2026PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Licensecaution

The artifact declares MIT but its license file is recognized as CC-BY-4.0, while a repository license file is also present. This mismatch creates genuine uncertainty about the release's licensing terms.

Maintainerscaution

One registry maintainer is consistent with a small publisher, but it provides limited publishing redundancy when combined with the repository's single active contributor.

Project backingcaution

The repository owner is a user account rather than an organization, so the one-person contributor concentration is not visibly backed by an organizational maintenance structure.

Release historycaution

This is a young package, 55 days old, with one release and no established release interval. That limits evidence of long-term stability but is not abandonment evidence by itself.

Repo bus factorcaution

All 30 recent commits came from one contributor, leaving maintenance highly dependent on a single person. The repository owner is an individual rather than an organization, so there is no shown organizational handoff buffer.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

QTE Technologies Co., Ltd

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform