Package Health

seiger/stask

The package includes tests, extensive documentation, and a stable release line. Maintenance is active, but the small contributor base and workflow configuration leave avoidable operational gaps.

Latest v2.1.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

67

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Project backingcaution

The repository is owned by an individual account rather than an organization, so the concentrated contributor activity represents a genuine continuity concern.

Repo bus factorcaution

Three contributors were active, but one supplied about 72% of recent commits. The second contributor remained active, partly reducing but not removing concentration risk.

Repo toolingcaution

Composer is used for builds, but no security-scanning tools were detected. This is a modest transparency and maintenance gap for a package handling background operations.

Security policycaution

The repository has no security policy, leaving vulnerability-reporting expectations and response guidance undocumented.

Workflow auditcaution

The single analyzed workflow has top-level write permissions and all five action references are unpinned. No untrusted checkout, script injection, or high-confidence audit finding was detected, so this is a hygiene caution rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Serhii Korneliuk

Direct Dependencies

DependencyLast ReleaseScore
evolution-cms/evo-ui
Version ^1.1
evolution-cms/evolution
Version ^3.5.7

Weekly Downloads

Info

Last Published
1 month ago
Created
11 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform