Package Health

tangible/ast

This is a small, early-stage but presently healthy package to depend on: it is not deprecated or archived, has a matching source repository under organization ownership, shows recent activity from three contributors, and includes tests in both the artifact and repository. The main reservations are its young age, pre-1.0 version, zero measured repository popularity, lack of a README and changelog, and absence of a repository security policy or security-scanning tooling. These are transparency and maturity gaps rather than evidence of abandonment, and the minimal dependency profile and lack of install-time scripts reduce operational risk.

Latest 0.1.3PackagistPackagist

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

72

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Package scaffoldingcaution

The artifact and repository both contain tests, and the file tree shows a unit test suite. The absence of a README and changelog reduces transparency, although the matching test coverage compensates for the missing packaged documentation to some extent.

Release historycaution

The package is only 98 days old with four releases, but releases have arrived regularly at a median interval of about 23 days and the latest release was published recently. This supports active development while leaving limited evidence of long-term maturity.

Repo popularitycaution

The repository has zero stars, forks, and watchers, indicating little visible adoption or community validation. For a small package this is supporting caution rather than a decisive health failure.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate for the package, while the missing security automation is a modest hygiene gap.

Security policycaution

The repository has no security policy. For a package intended as a dependency, this weakens vulnerability-reporting transparency, but it is not by itself evidence of unsafe maintenance.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Team Tangible

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
21 days ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform