Package Health

tacoberu/hayo

The project has a clear README, repository tests, and frequent recent releases. One contributor made only one commit in the last three months, while all six workflow actions are unpinned. No security policy adds a smaller transparency gap.

Latest v0.3.10PackagistPackagist

62%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Repo bus factorcaution

All recent commit activity comes from one contributor, leaving no demonstrated backup maintainer. The repository is user-owned rather than organization-backed, so this concentration is more consequential.

Repo commit activitycaution

Only one commit was recorded in the last three months, despite the recent release history. This is a meaningful maintenance-capacity concern, though the repository was pushed very recently.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, not evidence that the package is unsafe.

Version stabilitycaution

Version v0.3.10 is not a stable major release, so the API may still change, but it is not marked as a prerelease and recent releases contain no prerelease versions.

Workflow auditcaution

The sole workflow was fully analyzed with no untrusted checkout, injection, or high-severity findings, and it avoids broad top-level write permissions. However, all six action references are unpinned, reducing build reproducibility and supply-chain control.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Martin Takáč

Direct Dependencies

DependencyLast ReleaseScore
tacoberu/hayo-decoder
Version ~0.3.15

Weekly Downloads

Info

Last Published
3 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform