Package Health

stackshift/assets

This is a very young, pre-1.0 package with only three releases over 34 days and no recorded commits or active maintainers in the last three months, so its long-term maintenance and API stability are not yet demonstrated. The linked organization-owned repository is active in the sense that it is not archived and was pushed alongside the latest release, and the package has a focused file tree, tests, a README, no install-time scripts, and minimal runtime dependencies. However, the absence of a license, security policy, security scanning, and ongoing observed commit activity creates meaningful adoption risk; it is usable with caution, but should be pinned and evaluated for organizational support before becoming a critical dependency.

Latest v0.3.0PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Repo commit activitydanger

The repository records zero commits and zero active maintainers over the last three months, despite the recent release and push timestamps; sustained maintenance capacity is therefore unproven.

Licensecaution

No declared license and no license file were found in the artifact or repository, leaving the legal terms for dependency use unclear.

Release historycaution

The package is only 34 days old with three releases and a median interval of about 17 days, so it shows initial publishing activity but has little history from which to establish durability.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently negative for a small package, but it also provides no evidence of an active user or maintainer feedback loop.

Repo popularitycaution

The repository has zero stars, forks, and watchers. Popularity is supporting evidence rather than a verdict, but these counters provide no external adoption or resilience signal for this very young package.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
19 days ago
Created
1 month ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform