Package Health

revolution/niconico

A single contributor made the last two commits, and both workflows grant top-level write access. The repository has tests, security scanning, pinned actions, and a recent release, which supports continued maintenance.

Latest 3.2.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Health Score Breakdown

Maintainerscaution

Only one registry account can publish releases. That is a real resilience concern for this individually owned project, though the repository shows recent activity from the same maintainer.

Project backingcaution

The repository is owned by an individual rather than an organization, so the single-maintainer and concentrated-contributor risks are not buffered by visible organizational backing.

Repo bus factorcaution

One contributor made all two commits in the last three months, concentrating maintenance entirely in one person. The non-archived repository and recent release partly compensate, but do not remove the continuity risk.

Security policycaution

No repository security policy was found. For a small API client this is a transparency gap, but it is not severe enough to outweigh the active source and security tooling.

Workflow auditcaution

Both workflows grant top-level write permissions, which is broader than necessary, but the audit found no untrusted checkouts, script injection, or other findings, and all six action references are pinned. The permissions are a mild hygiene concern rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

kawax

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/guzzle
Version ^7.0

Weekly Downloads

Info

Last Published
1 month ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform