Package Health

sghimire/nepali-date-library

The MIT license, README, tests, and six recent commits provide a workable foundation. Its short release history means long-term maintenance is not yet proven; pin this version and reassess after a longer track record.

Latest 1.0.1PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

80

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Release historycaution

The package is only 64 days old with two releases about 16 days apart, so its release pattern is encouraging but its long-term maintenance record remains limited.

Repo bus factorcaution

All six recent commits came from one contributor, leaving maintenance dependent on a single person despite the recent activity.

Repo toolingcaution

Composer is used for builds, providing standard package tooling, but no security-scanning tool was detected, leaving security checks less explicit.

Security policycaution

The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it does not by itself indicate unsafe code.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and it scopes permissions at job level. However, all four action references are unpinned, leaving avoidable build reproducibility and action-update risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sandip Ghimire

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
2 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform