Package Health

rockett/weasyprint

This is a generally healthy and usable release: it has a six-year release history with 39 releases, eight releases in the last 12 months, a stable non-prerelease version, no registry deprecation, a linked non-archived repository, and clear licensing. The repository and artifact are well structured, include documentation, changelog and security policy files, and the artifact has no install-time lifecycle scripts. The main concerns are that recent repository activity is limited to two commits over three months from one contributor, the package has only one registry maintainer, and no security scanning tooling was detected. Repository tests compensate for the absence of packaged tests, but the narrow maintenance base warrants some dependency-review caution.

Latest v11.2.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

60

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access. That is a genuine continuity concern for a user-owned project, although repository release history and recent activity show that the maintainer is currently active.

Project backingcaution

The repository is owned by an individual user rather than an organization. This does not make the package unsafe, but it means the single-maintainer and bus-factor concerns are not offset by visible organizational backing.

Repo bus factorcaution

One contributor made all two commits in the last three months, producing a 100% top-contributor share. With a user-owned repository and no organizational backing, this creates a meaningful single-maintainer continuity risk.

Repo commit activitycaution

Only two commits were recorded in the last three months, indicating a low maintenance cadence. Recent releases partially compensate for this, but the repository activity itself is limited.

Repo toolingcaution

The repository uses build tooling through Just and Composer, but no security scanning tools were detected. The build tooling is positive, while the missing security automation is a hygiene gap rather than a severe health risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Mike Rockett

Direct Dependencies

DependencyLast ReleaseScore
composer/semver
Version ^3.4
—
—
symfony/process
Version ^7.4|^8.0
—
—
rockett/pipeline
Version ^4.1
—
—
illuminate/support
Version ^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
25 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform