Package Health

reportei/jigsaw

The MIT license, included tests, and release notes provide useful transparency for adopters. Unpinned workflow actions and the lack of a security policy leave avoidable maintenance and supply-chain hygiene gaps.

Latest 1.3.291PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

0

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

63

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historydanger

The package has 71 releases since 2015, but it has had no release in roughly six years; that strongly raises abandonment and compatibility risk.

Repo commit activitydanger

The repository recorded no commits and no active maintainers in the last three months, consistent with the long release pause and weakening evidence of ongoing maintenance.

Repository archivedcaution

The repository is not archived, which is a modest positive, but its last push was in July 2020 and does not offset the absent recent activity.

Security policycaution

No security policy was found in the linked repository, reducing transparency about vulnerability reporting and response for a package that may still be used in production builds.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout, injection, or high-confidence audit findings, but all 3 action references are unpinned, leaving a supply-chain hygiene gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Adam Wathan
Keith Damiani

Direct Dependencies

DependencyLast ReleaseScore
symfony/yaml
Version ^4.0|^5.0
—
—
illuminate/view
Version ^7.0
—
—
mockery/mockery
Version ^1.0.0
—
—
symfony/console
Version ^4.0|^5.0
—
—
symfony/process
Version ^4.0|^5.0
—
—

Weekly Downloads

Info

Last Published
6 years ago
Created
11 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform