Package Health

spora-ai/spora-plugin-memories

This is a promising and currently active package: it has nine releases in 42 days, was published recently, is not deprecated or archived, has substantial repository test coverage, and uses Composer and Sonar tooling. The main concerns are its early 0.x maturity, complete concentration of the last three months' 50 commits in one maintainer, absence of a security policy, and incomplete top-level GitHub Actions permission declaration. The organization-owned repository provides some continuity context, but the narrow active contributor base still creates a meaningful bus-factor risk.

Latest v0.5.0PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Health Score Breakdown

Dependency profilecaution

Five runtime dependencies, including the host core and a paired frontend package, are reasonable for a plugin but create coupling to the surrounding Spora package ecosystem.

Repo bus factorcaution

One contributor made 100% of the 50 recent commits, creating a significant bus-factor concern; the organization-owned repository offers some potential continuity but does not demonstrate a second active contributor.

Repo commit activitycaution

Fifty commits in the last three months show strong recent activity, but all were produced by one active maintainer, limiting independent maintenance capacity.

Security policycaution

No repository security policy was found, leaving vulnerability reporting and disclosure expectations undocumented.

Token permissionscaution

The only workflow lacks top-level permissions and uses job-level permissions only; although no top-level write permissions were detected, the permission posture is less explicit than ideal.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^4.7
spora-ai/spora-core
Version >=0.23.0 <2.0.0
symfony/event-dispatcher
Version ^8.0
spora-ai/spora-plugin-memories-frontend
Version >=0.1.0 <2.0.0

Weekly Downloads

Info

Last Published
12 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform