Package Health

quorum/exporter

The package is well documented, tested, licensed, and has no install-time scripts. Unpinned workflow actions and the lack of a security policy weaken release transparency, while organization ownership provides some continuity.

Latest v0.2.0PackagistPackagist

69%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Release historycaution

The package has six releases over more than 11 years, with no registry release in the last 12 months and a median interval of about 505 days. Recent repository activity partly offsets the slow publishing cadence, but the release history still raises maintenance concern.

Repo bus factorcaution

One contributor accounts for all recent commits, creating a meaningful continuity risk. Organization ownership offers some potential handoff capacity, but no second active contributor is shown.

Security policycaution

The repository has no security policy, which makes vulnerability reporting and response expectations less transparent for consumers.

Version stabilitycaution

Version v0.2.0 is not a stable major release, so compatibility may still change; however, it is not marked as a prerelease and has no recent prerelease pattern.

Workflow auditcaution

The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, script injection, or flagged findings. Both analyzed action references are unpinned, a modest reproducibility and supply-chain hygiene weakness.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Jesse Donat

Direct Dependencies

DependencyLast ReleaseScore
maennchen/zipstream-php
Version ~2.1
—
—

Weekly Downloads

Info

Last Published
3 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform